Operating System Notes

Learn how AssetLoom Network Scanner behaves across supported operating systems, including platform-specific permissions, commands, and network discovery limitations.

AssetLoom Network Scanner supports macOS, Windows, and Linux, but the way you run the scanner and grant the required system permissions differs by operating system.

You can use this guide when you need platform-specific instructions for running the scanner or troubleshooting permission-related discovery issues.

1. For macOS & Linux

Run the Scanner with Administrator Access

For the best discovery coverage on macOS/Linux, run the scanner with sudo.

For example sudo ./assetloom-scanner --config ./config.json --output ./devices.csv TARGET

Without elevated permissions, the scanner may still run, but ICMP or ARP discovery can be limited. You can run a dry run to check whether these protocols are available before scanning.

Make the Scanner Executable

If macOS returns a permission error when you try to run the downloaded scanner, make the binary executable: chmod +x ./assetloom-scanner

You normally need to do this only once for the downloaded binary.

If macOS Blocks the Scanner

macOS may prevent an unsigned downloaded binary from running.

Only run a Network Scanner binary that you downloaded from an official or organization-approved AssetLoom distribution channel.

If the scanner is blocked, review the macOS security message before proceeding and make sure the file is the AssetLoom release you intended to use.

Optional: Use Linux File Capabilities

If your organization permits Linux file capabilities, you may be able to grant the scanner raw-socket capability instead of running the entire scanner with sudo: sudo setcap cap_net_raw+ep ./assetloom-scanner

Keep in mind that file capabilities may be lost if you copy or replace the scanner binary.

2. For Windows

Run from an Administrator Terminal

For the best discovery coverage on Windows, open PowerShell or Command Prompt as Administrator before running the scanner.

For example: .\assetloom-scanner.exe --config .\config.json --output .\devices.csv TARGET

Running without Administrator access may limit some discovery methods. Use a dry run to check protocol capability if you are unsure.

Keep the .exe Extension

Unlike macOS and Linux, the Windows scanner should keep its .exe extension.

If you kept the original downloaded filename, your command may look like: .\assetloom-scanner.exe --version

You can replace the filename in the examples with the actual scanner filename on your computer.

Quick Comparison

macOSWindowsLinux
Recommended elevated accesssudoAdministrator terminalsudo
Executable permission may be requiredYesNoYes
Typical scanner command./assetloom-scanner.\assetloom-scanner.exe./assetloom-scanner
Path style./config.json.\config.json./config.json
Alternative raw-socket capability——setcap where permitted

If discovery behaves differently than expected on your operating system, run a dry run and review Protocol Capability first. This will show whether ICMP, ARP, and the other configured discovery methods are available on the scanner host.


What’s Next?