Point it at a host and it tells you what the device is โ OS & software (from service banners), plus VPN gateways, management consoles (F5, Citrix, Palo, iLO/iDRAC), SNMPv3 engine vendor, and DNS/NTP identity leaks. Read-only reconnaissance โ no credentials, no exploitation. Public hosts only.
nmap -sV banners + web-portal, SNMPv3, DNS & NTP fingerprints. A full scan takes a few seconds per host.