Network scanner
Findy looks at the Wi-Fi network you are actually joined to and reports what responds: which services are advertised, which camera-associated ports are open, and what has appeared since your last scan of that network.
The network scanner requires the Findy subscription ($39.99 per year in the US). The Bluetooth scanner, magnetic checks and guided inspection information are free.
What the scanner does
It runs two passes over the local network, and they answer different questions.
1. Bonjour / mDNS browse
Findy listens for devices that advertise themselves on the local link. It declares and browses
for _rtsp._tcp and _http._tcp — the service types a streaming camera or
a device with a web control panel commonly publishes.
Devices that advertise nothing simply do not appear in this pass.
2. TCP-connect port probe
Findy attempts a plain TCP connection to each address on the local /24, on a fixed set of ports associated with cameras, recorders and their control interfaces.
A device with all of these ports closed is invisible to this pass.
The ports Findy probes
| Ports | Commonly associated with |
|---|---|
554, 8554 | RTSP video streaming |
80, 443, 8080, 8000, 88 | Web and control interfaces on cameras and many other devices |
37777, 34567, 8899 | Vendor protocols used by recorders and network cameras |
Findy fingerprints a device as a possible camera from the combination of ports that answer — an RTSP port carries far more weight than a web port, because port 80 is open on printers, routers, televisions and smart plugs.
New since your last scan
Findy remembers what it saw on each network and badges devices that were not present the previous time you scanned that same network. In a rental or hotel room, something appearing between an arrival scan and an evening scan is a reasonable thing to look at.
It is also a weak signal on its own: devices join and leave networks constantly, phones and laptops of other guests come and go, and DHCP hands out different addresses over time.
What the scanner cannot see
- Devices on a different network are invisible. A camera on the host's private network, or on a guest network you have not joined, will not appear.
- Cameras that record to a local card and never connect to Wi-Fi will not appear.
- Cellular-connected cameras will not appear.
- Powered-off devices will not appear.
- Many networks — hotels especially — isolate clients from one another, so almost nothing is reachable and the scan may return very little.
- A camera using only ports outside the probe list will not be fingerprinted.
iOS does not give apps access to the ARP table. Findy therefore cannot read hardware addresses and cannot look up a manufacturer from one. The device inventory is keyed by IP address only, which is why an address that changes between scans may look like a new device when it is not. Any app claiming to name the manufacturer of every device on your network from an iPhone is claiming access it does not have.
Device discovered is not camera identified
These are different claims and Findy keeps them separate. A device advertising a video service under a camera-suggestive name is genuinely worth investigating. A device with no name and no recognisable service is simply unidentified — and most home and hotel networks are full of those.
Findy marks each discovered device either as ordinary or as showing camera-related indicators, and shows the specific reason it was marked. There is no "confirmed" state and no certainty score.
| Label | What it means |
|---|---|
| Ordinary | Nothing Findy observed about the device is associated with cameras. |
| Shows camera-related indicators | One of the checks below matched. Findy totals these and reports the count as the number of suspicious devices. |
The reason shown beside a marked device is one of the following:
- a name matching a manufacturer known for cameras, shown as "Likely <vendor> camera";
- a name matching a camera-related keyword, shown as "Name matches <keyword>";
- a streaming or surveillance service advertised on the network;
- an open port associated with cameras.
Findy shows the reason behind every flag. Be aware that a device whose name matches a manufacturer known for cameras is flagged on that basis alone — many such manufacturers also make televisions, doorbells and routers, so treat a name-only match as a starting point rather than a finding.
Getting a scan worth reading
- Join the same Wi-Fi network you want to inspect. Findy can only see the network you are on.
- Scan once shortly after you arrive, so you have a baseline for that network.
- Open any device flagged with a web port in a browser and see what answers. Often it identifies itself immediately.
- Scan again later. Compare the badges for anything that has appeared since.
- Treat an empty or near-empty result as inconclusive, not as an all-clear — client isolation produces exactly that.
- Follow up anything interesting with a physical look at the room.
Related
Camera inspection tools cover the devices a network scan cannot see. The full limitations page explains where every method falls short.
Last reviewed 2026-07-23 · Written and reviewed by the Findy developer.