Setup & requirements
What just works — and the few things you install once
Most of SubnetSlinger runs the moment you launch it. A handful of tools use software you already have or install once. Here's exactly what, why, how — and what to do when it doesn't work.
✓ Works out of the box — nothing to install
The core toolkit runs on a clean install — no admin, no extra software. Launch and go.
⊕ Optional add-ons — install only what you'll use
Each one is one-time and independent. Skip any you don't need.
Packet Capture
1-time installLive packet analyzer — decode traffic, export .pcap.
Needs a capture driver — the same one Wireshark uses.
Check "WinPcap API-compatible mode". Admin required — it is a kernel driver, so it can't ship inside the app.
If it doesn't work
No interfaces listed? Windows: reboot after installing Npcap. Linux: run install-linux.sh, then getcap ./subnetslinger-capd should show the caps. The app tells you when the driver is missing.
CLI wrappers
1-time installA friendly form over tools you already drive: nmap, curl, dig, mtr, tcpdump, openssl.
SubnetSlinger builds the command and runs the copy you install — it bundles none of them.
winget install Nmap.Nmapcurl & dig are built into Windows; add others via winget
If it doesn't work
“X not found on PATH”? Install just that tool (above) and reopen the form — it names the exact one that's missing.
SFTP / SCP receive
1-time installLet devices push configs/images TO this machine (the Transfer + Local servers 'receive' side).
Uses your OS's own OpenSSH server on TCP 22.
Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0admin PowerShell
Start-Service sshdIf it doesn't work
The panel detects the service and shows the exact enable commands live. Sending FROM the app never needs this — only receiving does.
Lab Testing — throughput
1-time installMeasure real bandwidth between two machines (iperf3), plus a chaos/latency monitor.
The throughput test drives iperf3 — needed on BOTH ends.
winget install iperf3If it doesn't work
Windows “cygwin1.dll was not found”? The iperf.fr build is Cygwin-based — keep cygwin1.dll in the same folder as iperf3.exe, on PATH.
Local AI — Ollama
1-time installRun the Deputy/Posse AI fully offline & free — nothing leaves your machine.
SubnetSlinger just talks to Ollama; you pull the model. (Cloud AI needs no install — just your key.)
ollama pull llama3.1If it doesn't work
The Deputy drives tools, so the model MUST support function-calling — llama3.1, qwen2.5, mistral. A “no tools” error = pick a tool-capable model. Each is a 4–40 GB download.
Deputy MCP hosts (advanced)
1-time installConnect the AI to external MCP servers (vendor devices, source-of-truth, monitoring).
Their toolchains are yours to install: Node.js for npx servers, Python + uv for uvx servers.
If it doesn't work
Servers run as local child processes over stdio — no inbound ports. Optional; skip unless you're wiring the AI to external systems. This is the Deputy's MCP client — it works on every desktop, Linux included. Running SubnetSlinger as an MCP server (so other AI apps can call its tools) is in the Windows build, not Linux yet.
🪟 Windows: winget commands assume the built-in Windows Package Manager (Win 10/11). Npcap and OpenSSH need admin.
Verify your Linux download
Prove the Linux build is genuine — even if this site is compromised
Straight talk: the Linux build is a direct download from this site — it is not distributed or reviewed through Snap, Flathub, or any store. You get the tarball straight from us, so no third party is vouching for the bits. This section is how you check them yourself.
(Windows is different: it installs from the Microsoft Store, where Microsoft signs and hosts it — there's nothing to hand-verify. The GPG flow below is for the Linux x86-64 tarball; macOS is verified with Apple's own tools — see "Verify the macOS build" below.)
The gold standard below is the GPG signature: the private signing key lives offline, never on this server or in any repo — so even if someone swapped the download or edited this very page, they could not forge a signature that verifies against our public key.
Check the hash (quick, but not enough on its own)
Download SHA256SUMS and SHA512SUMS next to the tarball, then run these in the download folder:
sha256sum --ignore-missing -c SHA256SUMSsha512sum --ignore-missing -c SHA512SUMSA matching hash only proves the file matches this page's number. If an attacker can rewrite the download, they can rewrite the number too. That's why the hash alone is weak — treat it as a fast smoke test, then do Step 2.
Verify the GPG signature (this is the real check)
GnuPG is preinstalled on most distros — otherwise sudo apt install gnupg (or dnf/pacman).
Grab the public key and the .asc signature files, then run:
gpg --import subnetslinger-signing-key.ascgpg --verify SHA256SUMS.asc SHA256SUMSgpg --verify subnetslinger-1.2.0.0-linux-x64.tar.gz.asc subnetslinger-1.2.0.0-linux-x64.tar.gzA good result says Good signature from "SubnetSlinger (AISMITH PDX LLC) …". Then confirm the key is ours by matching this fingerprint, which we also publish off this site (release notes, changelog) so a single compromised page can't fake it:
Signing key fingerprint
6285 1F0E BBD5 AA9D 6E3C E11A 9433 D73B DB83 622C
A “gpg: BAD signature” or a fingerprint that doesn't match means do not run the file — delete it and email sheriff@subnetslinger.com.
What to download for verification
- • Public key:
https://subnetslinger.com/subnetslinger-signing-key.asc - • Checksums:
SHA256SUMS,SHA512SUMS(+.ascsignatures) — next to the tarball - • Tarball signature:
subnetslinger-1.2.0.0-linux-x64.tar.gz.asc
Filenames use the version you downloaded — swap 1.2.0.0 above for it if it differs.
Verify the macOS build
The macOS .dmg is signed with an Apple Developer ID certificate and notarized by Apple, so a clean Mac accepts it with no warning. You can confirm it yourself — in the download folder, and after dragging the app to Applications:
shasum -a 256 -c SubnetSlinger-1.2.0.dmg.sha256spctl -a -t execute -vvv /Applications/SubnetSlinger.appcodesign --verify --deep --strict --verbose=2 /Applications/SubnetSlinger.appsource=Notarized Developer ID and valid on disk mean Apple vouches for the bits. The release also ships a detached GPG .asc and both SBOMs (CycloneDX + SPDX) next to the dmg — verified with the same offline key as the Linux build: gpg --verify SubnetSlinger-1.2.0.dmg.asc SubnetSlinger-1.2.0.dmg.
Still stuck?
Every one of these is optional and independent — the core toolkit works without any of them. If a tool still won't run after installing its dependency, see the Support page.