Installation
NetsCLI publishes command-line binaries and desktop installers through GitHub Releases. The CLI/TUI binary is named netscli. The desktop app is distributed as NetsCLI Desktop.
Recommended installs
Section titled “Recommended installs”| Platform | Recommended path | Installs |
|---|---|---|
| Windows | winget install netscli |
CLI and TUI |
| Windows | winget install netscli-gui |
Desktop app |
| macOS | Homebrew or install script | CLI and TUI |
| macOS | brew install --cask fstubner/tap/netscli-gui |
Desktop app |
| Linux | Install script, Homebrew, AUR, or release download | CLI and TUI |
| Linux | .deb, AppImage, or yay -S netscli-gui-bin |
Desktop app |
| Rust users | cargo install netscli |
CLI and TUI from crates.io |
| Node users | npx netscli |
CLI and TUI from npm, no install step |
Windows
Section titled “Windows”Use winget for the hash-verified install path:
winget install netscliThe desktop app is distributed separately:
winget install netscli-guiIf a short name ever matches more than one package, use the full
identifiers, fstubner.netscli and fstubner.netscli.gui.
Scoop is also supported, for both the CLI and the desktop app:
scoop bucket add fstubner https://github.com/fstubner/scoop-bucketscoop install netscliscoop install netscli-guiOr the PowerShell install script, which picks the right download for your machine:
iwr -useb https://netscli.com/install.ps1 | iexDirect Windows downloads are on the
releases page. From
0.3.3 on, the .exe downloads and the .msi installer are signed, so Windows
names the publisher instead of showing an unknown one. From 0.3.4 the desktop
app inside the installer is signed too. While the certificate is new,
SmartScreen may still show a warning the first time you run one.
Use Homebrew when available:
brew tap fstubner/tap && brew install netscliOr use the install script:
curl -fsSL https://netscli.com/install.sh | bashFor the desktop app, use the Homebrew cask:
brew install --cask fstubner/tap/netscli-guiOr download the .dmg for Apple Silicon or Intel from the
releases page.
The desktop app is not notarized by Apple, so macOS blocks its first launch, whichever way you installed it. Open it once, then go to System Settings → Privacy & Security and click Open Anyway. You only need to do this once. (Right-click → Open no longer does this on macOS 15 and later.)
Use the install script:
curl -fsSL https://netscli.com/install.sh | bashInstall with Homebrew on Linux when you use Linuxbrew:
brew tap fstubner/tap && brew install netscliOn Arch-based systems with an AUR helper:
yay -S netscli-binFor the desktop app, download the .deb (Debian, Ubuntu and derivatives) or
the AppImage (any distribution) from the
releases page:
sudo apt install ./netscli-gui-linux-x86_64.debchmod +x netscli-gui-linux-x86_64.AppImage./netscli-gui-linux-x86_64.AppImageOn Arch-based systems:
yay -S netscli-gui-binIf the desktop window opens black or blank
Section titled “If the desktop window opens black or blank”On some Linux machines the desktop app’s window opens but stays black or blank. It is a graphics driver problem, and has been seen on virtual machines.
Close the window and open the app again. The app notices the blank launch and switches to a safer drawing mode the next time, so the second launch usually works.
If it is still blank, start it once with:
netscli-gui --disable-gpu-compositingThe app remembers this, so later launches from the desktop icon keep working. To go back to the default:
netscli-gui --gpu-compositingWindows and macOS are not affected, and the two options do nothing there.
If Rust is installed:
cargo install netscliCargo installs the CLI/TUI binary. It does not install the desktop app.
If Node 18 or newer is installed, you can run NetsCLI without installing anything:
npx netscli --helpOr install it globally:
npm install -g netsclinpm downloads only the prebuilt binary for your platform. Published targets are Linux x64 and arm64, macOS x64 and Apple Silicon, and Windows x64. The Linux arm64 binary needs glibc 2.39 or newer.
What the npm build leaves out:
- Packet capture. It needs libpcap or Npcap on the machine, which npm cannot arrange. Use a package from the sections above if you need it.
- The desktop app. npm installs the CLI and TUI only.
If you mainly want the MCP server, see MCP server. The npm package is one of three ways to connect it.
Updating
Section titled “Updating”Use the same package manager you installed with.
Update the CLI and TUI on Windows:
winget upgrade fstubner.netscliUpdate the desktop app on Windows:
winget upgrade fstubner.netscli.guiUpdate a Homebrew install:
brew upgrade netscliThe desktop app can also update itself from 0.3.4 on. It checks for a new release when it opens and offers to install it. See Updates for which installs can do this.
Update a global npm install:
npm update -g netsclinpx netscli may reuse a copy it has cached. To be sure you get the newest
release, run npx netscli@latest.
For a direct download, get the latest GitHub release and replace the previous install with the matching package for your platform.
Verifying a download
Section titled “Verifying a download”Every CLI and desktop release asset is checksummed and signed, and both can be checked before you run anything.
Checksums
Section titled “Checksums”Each asset ships a .sha256 sidecar next to it on the release page. The
install scripts fetch and check it for you, and refuse to install if it is
missing. To check a manual download yourself:
# Linux / macOScurl -fsSLO https://github.com/fstubner/netscli/releases/latest/download/netscli-linux-x86_64curl -fsSLO https://github.com/fstubner/netscli/releases/latest/download/netscli-linux-x86_64.sha256sha256sum -c netscli-linux-x86_64.sha256# Windows(Get-FileHash -Algorithm SHA256 .\netscli-windows-x86_64.exe).Hash.ToLower()# compare against the contents of netscli-windows-x86_64.exe.sha256Signatures
Section titled “Signatures”A checksum only proves the file matches its own sidecar, and both come from the same place. The signature is what ties the asset to the workflow run that built it.
Every asset is signed with Sigstore
cosign by the release workflow,
and the signature is tied to the exact run that built it. Each asset ships a
.sig and a .pem beside it:
cosign verify-blob \ --signature netscli-linux-x86_64.sig \ --certificate netscli-linux-x86_64.pem \ --certificate-identity-regexp 'https://github.com/fstubner/netscli/.github/workflows/release\.yml@.*' \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ netscli-linux-x86_64Substitute the asset name you downloaded. The same command works for the desktop .msi, .dmg, .deb and .AppImage. It needs the cosign
CLI. A pass
confirms the asset was built and signed by this repository’s release workflow
and has not been altered since.
This is separate from the code signing Windows and macOS check. The Windows downloads carry a Windows signature from 0.3.3 on, and the macOS app is not notarized. See the Windows and macOS sections above for what your system will say on first run.
Packet capture
Section titled “Packet capture”None of the installs above include packet capture. The desktop installers, the standard CLI downloads, and cargo install netscli are all built without it, so none of them needs libpcap or Npcap. The rest of this section is how to get a build that has it.
Normal scan, discovery, DNS, ARP, ping, trace, and interface workflows are unaffected and need none of this.
If you do want packet capture, you need both a build that has the feature compiled in and the system capture library.
CLI with packet capture
Section titled “CLI with packet capture”The install script does both at once. It selects the -pcap build and installs the system library.
curl -fsSL https://netscli.com/install.sh | NETSCLI_PCAP=1 bash$env:NETSCLI_PCAP=1; iwr -useb https://netscli.com/install.ps1 | iexOn Windows this runs the Npcap installer, which needs administrator rights. Add NETSCLI_SKIP_NPCAP=1 (or NETSCLI_SKIP_LIBPCAP=1 on Unix) if you manage the capture library yourself.
Alternatively, download the -pcap asset directly from the latest release (netscli-linux-x86_64-pcap, netscli-macos-aarch64-pcap, netscli-windows-x86_64-pcap.exe, and so on) and install the capture library separately. There is no -pcap musl build.
Or build it yourself, which needs the development headers (libpcap-dev on Debian/Ubuntu, or the Npcap SDK on Windows):
cargo install netscli --features pcapDesktop app with packet capture
Section titled “Desktop app with packet capture”There is no published desktop installer with packet capture. The Packet Capture tool appears in the app but shows setup guidance instead of running. To get a capture-capable desktop build you have to build from source:
cd apps/netscli-guinpm installnpm run tauri build -- --features pcapSystem requirements
Section titled “System requirements”| Platform | Requirement |
|---|---|
| Windows | Npcap installed. wpcap.dll lives in C:\Windows\System32\Npcap\, which is not on PATH by default. Add it, or let NETSCLI_PCAP=1 do it. |
| Linux | libpcap installed, plus capture permissions (CAP_NET_RAW or root). |
| macOS | libpcap available, plus capture permissions where required. |
Checking what you have
Section titled “Checking what you have”netscli doctor works on every build and reports whether packet capture is compiled in and whether the runtime library is present:
netscli doctorNote that netscli pcap --check only exists on builds that were compiled with the feature. On a standard build the subcommand is absent entirely, and you will get an “unrecognized subcommand” error rather than a useful message. Use doctor to find out which build you have.