# RustScan: A Fast Port Scanner with Scripting Engine and Nmap Integration

> RustScan is a GPL-3.0 port scanner written in Rust that scans all 65,535 ports in seconds and automatically passes the discovered open ports into Nmap for deeper analysis. It includes a scripting engine supporting Python, Lua, and Shell scripts, and uses adaptive learning to tune its behavior to the host operating system over time.

**bee-san/RustScan** — 🤖 The Modern Port Scanner 🤖

- Repository: https://github.com/bee-san/RustScan
- Stars: 20,477 · Forks: 1,386
- Language: Rust
- License: GPL-3.0
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/bee-san-rustscan

## What RustScan Does and Who It Is For

RustScan is a port scanner that focuses on speed at the port discovery stage. The README documents the advertised speed as finding open ports across all 65,535 ports in 3 seconds at its fastest. The tool is aimed at penetration testers, CTF participants, and network administrators who need fast host enumeration before a more detailed Nmap scan.

Once RustScan identifies open ports, it can automatically pass those ports to Nmap with the appropriate flags, so Nmap only runs its slower service detection and scripting against ports that are confirmed open rather than scanning all 65k. This two-phase approach (fast open port discovery with RustScan, then targeted deep analysis with Nmap) is the primary workflow the tool is designed for.

The README also notes that RustScan aims to be fully accessible, describing it as 'one of the first penetration testing tools that aims to be entirely accessible', with continuous integration testing to verify accessibility properties.

## Speed: Adaptive Learning and CI-Enforced Performance

RustScan's speed comes from asynchronous I/O. The Cargo.toml shows async-std as a core dependency alongside futures. The tool opens connections asynchronously rather than serially, allowing it to probe many ports in parallel without blocking.

Two mechanisms are documented for maintaining speed. First, the continuous integration system runs HyperFine benchmarks on every pull request to verify that new code does not significantly slow down the scanner. The README states that if a pull request makes RustScan significantly slower than the previous version, the CI fails and the code cannot be merged until performance is restored.

Second, the Adaptive Learning feature tunes RustScan to the scanning environment and to the user's patterns over time. The README describes this as basic mathematics rather than machine learning, and notes that the feature list changes as new adaptive behaviors are added. The rlimit crate in Cargo.toml is used to manage file descriptor limits, which is relevant since fast scanning opens many concurrent sockets.

## Installing RustScan

RustScan is available in many package repositories. The README shows two package-manager installs:

On macOS:

```bash
brew install rustscan
```

On Arch Linux:

```bash
pacman -S rustscan
```

The README states that the only officially supported installation method is Cargo:

```bash
cargo install rustscan
```

Binaries are also available on the GitHub releases page for users who do not have Rust or Cargo installed. The Cargo.toml confirms the package name is rustscan and the current version is 2.4.1. The Makefile shows that release builds use cross-compilation for Linux (x86_64 unknown-linux-musl) and macOS (x86_64-apple-darwin) targets.

## The Scripting Engine: Nmap Integration and Custom Scripts

RustScan includes a scripting engine that runs after port discovery. The README lists Python, Lua, and Shell as supported scripting languages. The primary use case is piping the discovered open ports into Nmap, which is built in as a first-class operation. Beyond Nmap, scripts can run any analysis on the discovered ports.

Examples given in the README include running smb-enum if SMB is found open, or writing custom scripts in any supported language to handle specific services. This makes the scripting engine an extension point for building custom enumeration workflows on top of the port discovery results.

The README points to an external documentation page (extensible-2) for more details on writing scripts, though the content of that page is not included in the repository directly. The config.toml file at the repository root is documented as the configuration location for the tool's settings and scripting configuration.

## Accessibility and Platform Coverage

The README devotes a section to accessibility, stating that most penetration testing tools are not accessible and that RustScan has CI testing aimed at ensuring it remains accessible. The Cargo.toml includes colored 3.1.1, colorful 0.3.2, ansi_term 0.12.1, and anstream 1.0.0 as color-related dependencies, which suggests the accessibility work relates to color output that is legible to color-blind users and screen-reader-compatible terminal output.

The package builds for Linux (musl static binary), macOS, and the Makefile shows cross-compilation support. The Cargo.toml shows hickory-resolver as the DNS resolver dependency with dns-over-rustls support, and cidr-utils for CIDR range scanning, which confirms that file input (a list of hosts) and CIDR notation (scanning a subnet) are supported.

IPv6 and file input are listed in the README as standard features. These make RustScan suitable for scanning internal network ranges rather than only individual hosts.

## Where RustScan Falls Short

RustScan does not perform service detection, OS fingerprinting, or script-based vulnerability checks on its own. These capabilities come from Nmap, which RustScan feeds results into. If Nmap is not installed, the Nmap integration does not work. The Cargo.toml package.metadata.deb section lists nmap as a recommended dependency for the Debian package build, which confirms this dependency.

The Adaptive Learning feature improves RustScan's behavior for the scanning environment, but the README states this is based on basic math and does not describe what specific parameters are adjusted or stored. Users who need deterministic, reproducible scan behavior may find this feature unpredictable.

The ulimit behavior is worth noting. RustScan attempts to open many file descriptors simultaneously. On systems with low file descriptor limits, scans may fail or produce incomplete results. The rlimit dependency handles this, but the README does not document what minimum ulimit is required or what happens when the limit is reached mid-scan.

## RustScan versus Nmap

Nmap is the standard tool for port scanning and network discovery. It performs port scanning, service version detection, OS fingerprinting, and script-based checks (NSE scripts) in a single tool. RustScan does not replace any of these functions; its value is reducing the time spent on the initial port discovery phase.

A typical Nmap full-port scan (nmap -p- <host>) is slower than RustScan's discovery because Nmap's default timing settings are conservative. RustScan scans faster by accepting more connection failures and using higher concurrency, then hands off only the confirmed open ports to Nmap for analysis. This means the final output is still an Nmap result set; RustScan functions as a speed optimization in the workflow.

The scripting engine in RustScan provides some overlap with Nmap's NSE scripts, but for most use cases the scripts are simpler (running a specific tool when a specific port is found open) rather than the full service detection logic that NSE scripts perform. Teams that use Nmap exclusively and find full-port scans fast enough for their environment gain little from adding RustScan to the pipeline.

## Conclusion

RustScan is the right tool for penetration testers and network administrators who need to reduce the time spent on the initial port discovery phase and want to forward those results directly into Nmap for service enumeration and script execution. It is not a replacement for Nmap: it does not perform service version detection, OS fingerprinting, or script-based vulnerability testing on its own. Before deploying in automated pipelines, review the adaptive learning behavior and the default ulimit settings, since RustScan may attempt to open many file descriptors and could fail silently if the system limit is too low.

## FAQ

### What is RustScan?

RustScan is a GPL-3.0 port scanner written in Rust that discovers open ports across all 65,535 ports in seconds using asynchronous I/O. It can automatically pipe the discovered open ports into Nmap for service detection and further analysis.

### Does RustScan use Nmap?

RustScan can automatically pass its discovered open ports to Nmap for deeper analysis, but it does not require Nmap. Service version detection, OS fingerprinting, and NSE script execution come from Nmap; RustScan only performs the initial port discovery phase.

### How do you use RustScan?

Run rustscan against a target host or CIDR range. RustScan discovers open ports using asynchronous connections and can pipe the results to Nmap with the -a flag. IPv6, CIDR ranges, and file input of host lists are all supported. The config.toml file at the user configuration path stores scan settings.

### How do you install RustScan on Kali Linux?

RustScan can be installed via Cargo with cargo install rustscan, which requires a Rust toolchain. Binary packages are available on the GitHub releases page for users without Cargo. The README recommends using a package manager when one is available.

## Sources

- [bee-san/RustScan on GitHub](https://github.com/bee-san/RustScan)
- [Issues](https://github.com/bee-san/RustScan/issues)
- [License: GPL-3.0](https://github.com/bee-san/RustScan/blob/master/LICENSE)
- [README](https://github.com/bee-san/RustScan/blob/master/README.md)
- [Releases](https://github.com/bee-san/RustScan/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/bee-san-rustscan
