Deploy EdgeWatch
Start with Docker, create your administrator account, and connect to the console.
Your network. No surprises.
Scan your network. Learn what belongs. Get notified when something changes.
The video could not load. Watch it on GitHub.
IPs, CIDRs, and DNS names.
On your schedule.
Build an expected surface
from complete observations.
Review confirmed incidents.
Keep the original history.
Deploy EdgeWatch
Start with Docker, create your administrator account, and connect to the console.
Monitor your network
Choose your targets, run a scan, and establish an expected surface.
Configure your deployment
Understand the boundary between YAML settings and console administration.
Build and contribute
Set up Go and Node.js, run the checks, and work on EdgeWatch or its documentation.
Built for the long watch
Know what belongs on your network. When something changes, have the evidence to understand it.
One Docker image. An embedded console.
SQLite storage on your host.
Only monitor systems you own or are authorized to assess.
Watch IPs, CIDRs, and DNS names with recurring jobs. Keep each network on its own schedule.
Monitoring jobsScan TCP and UDP with Nmap, or discover TCP ports with Naabu and confirm them with Nmap.
Scanners and profilesCompare ports, services, and DNS against your baseline. Review host evidence and keep the original history.
Baselines and incidentsRoute incidents and optional release alerts to named Shoutrrr destinations, with credentials encrypted at rest.
Notification routingGive each person the right role, protect accounts with TOTP, and publish only the status you choose.
Accounts and public statusResume completed work after a timeout or restart. Incomplete observations never rewrite your expected surface.
Resumable scanning