EdgeWatch is a self-hosted network-surface monitor. It schedules TCP and UDP scans, learns what is expected, and notifies you when the observed surface changes. It ships as one Docker image with an embedded web console and SQLite storage.
EdgeWatch.mp4
Only scan systems you own or are authorized to assess. Full-range UDP scans can take many hours and generate significant traffic.
Requirements: Docker Engine 25 or later and Docker Compose v2 on a host supporting host networking and scanner capabilities. From a checkout of this repository:
cp config.example.yaml config.yamlCreate the data directory for your Docker mode. For standard rootful Docker:
sudo install -d -m 0750 -o 0 -g 0 ./dataFor rootless Docker:
install -d -m 0750 ./dataWith user-namespace remapping, use the host UID mapped to container UID 0. The container runs as UID 0 with filesystem capabilities dropped; keep data owned by that mapped identity and do not use world-writable permissions. For an existing deployment, read the installation and backup guides before changing ownership, mounts, or images.
docker compose pull
docker compose up -d
docker compose logs edgewatch | grep setup_tokenOpen http://127.0.0.1:8080 and create the first administrator with the one-time setup token, which expires after 15 minutes. The listener is loopback-only. For a remote host, tunnel from your workstation:
ssh -L 8080:127.0.0.1:8080 user@docker-hostThen add notification destinations and create your first monitoring job in the
console. Runtime state and generated encryption keys live in ./data; back
them up together.
The full user, operator, and maintainer documentation is available at
edgewatch.offsec.nl. The website source lives in
docs/.
- Installation and first scan
- Updates, reverse proxies, and container hardening
- Jobs and incidents, scanning, and notifications
- Accounts and public status and business units
- Configuration, CLI, database compatibility, and API compatibility
- Backup and recovery and local development
Report vulnerabilities privately as described in SECURITY.md.
Copyright (c) 2026 Bart. Released under AGPL-3.0-only; bundled components retain their separate licenses in THIRD_PARTY_LICENSES.md. Releases before v0.25.0 retain their published MIT terms. See the license and source-code guide for the source link requirements when deploying a modified build.