What Canelo Actually Is
Canelo is a tool built for network reconnaissance and vulnerability scanning. It wraps around several well-known open source utilities and strings them together so you can run a full assessment without manually chaining CLI commands. The core idea is straightforward: feed it a target range, pick a profile, and it handles service discovery, port scanning, and exploit enumeration in one pass. It has gained traction among penetration testers who need a faster workflow than the manual Nmap-to-Nikto-to-MSFConsole dance. The installation is relatively painless if you have Python 3.9 or later and pip. Clone the repository, create a virtual environment, and run the installer script. I have it sitting on a Kali VM alongside another scanner because the edge-case behavior with certain internal /24 ranges differs noticeably from the default output. One specific problem I ran into: when scanning subnets with a lot of ICMP unreachable responses, Canelo sometimes hangs on the port scan phase. The workaround is simple — run the scan with the --no-icmp flag and set the timing template to -T3. That skips the noisy ICMP probes and keeps the scanner moving. It adds maybe five minutes to the run but stops the deadlocks entirely. After installation, the basic command structure looks like this:
canelo scan --target 192.168.1.0/24 --profile aggressive The profile flags tell the tool which combination of reconnaissance modules to run. The aggressive profile enables port scanning, service version detection, and vulnerability enumeration. There is also a stealth profile that limits scan intensity for environments where you want to stay under the radar of IDS systems. I usually default to stealth when testing client networks during business hours. Aggressive goes out the window after hours or in lab settings.
Understanding the Scanning Profiles
Canelo organizes its scanning logic into profiles rather than individual toggles. This design decision speeds up operation but reduces fine-grained control. The three main profiles are stealth, standard, and aggressive. Stealth uses UDP scan delays and TCP SYN evasion techniques. Standard does a normal SYN scan with service version detection. Aggressive throws everything at the target including default credential checks and known exploit verification. Here is the counter-intuitive part most beginners miss: the aggressive profile is not always the most thorough. Because it prioritizes speed, it sometimes skips slower but more complete UDP service identification. I learned this the hard way during a client engagement where an aggressive scan reported a closed SNMP service, but a follow-up manual Nmap UDP scan revealed an active SNMP community string. The aggressive profile's UDP phase runs with a much shorter timeout than a dedicated tool would, so some services fall through the cracks. If your assessment requires complete coverage, run the aggressive profile first and then follow up with targeted manual scans on any ambiguous results. Another common pitfall involves the exploit enumeration phase. Canelo matches open ports against a local vulnerability database and runs checks automatically. The problem is that many of these checks are based on signature matching rather than actual exploitation. A banner grab might match a known vulnerable version string, but that does not mean the target is exploitable. I have seen junior testers report false positives to clients because they trusted the automated output without manual verification. Always validate flagged vulnerabilities independently before including them in a report.
Get the Full Details

Running Your First Scan
Before running anything, configure your target list. Canelo accepts single IPs, CIDR ranges, and text files containing multiple targets. I keep a persistent text file for each client engagement with all discovered subnets. Feeding that file to Canelo saves significant setup time between scans. The command to load a target file looks like this: canelo scan --targets-file clients/acme-corp/subnets.txt --profile standard --output reports/acme-corp-scan.json The output format matters more than most people realize. Canelo supports JSON, CSV, and HTML reports. JSON is the most useful if you plan to parse results with scripts. HTML works better for handing to clients who do not read terminal output. CSV is the middle ground and integrates cleanly into spreadsheets for tracking remediation. I typically run scans twice — once to JSON for my own analysis and once to HTML for the final deliverable.
Scan duration depends heavily on the target size and the chosen profile. A standard scan across a /24 subnet usually completes in about twenty to forty minutes. The aggressive profile on the same range takes longer because of the additional service checks, often around forty-five to ninety minutes depending on response rates. UDP scanning adds significant time because of the inherent slowness of UDP reconnaissance. If you know the target primarily runs TCP services, skip the UDP module and cut scan time roughly in half.
Limitations and When Canelo Falls Apart
Canelo is not a silver bullet. It struggles with highly fragmented or asymmetric network environments where return paths differ from forward paths. In those cases, the scanner may report hosts as down when they are actually reachable through different routing. It also has limited support for cloud-native environments with ephemeral IP allocation. Running Canelo against AWS or Azure instances without proper API integration means you are guessing at target ranges, which is inefficient and often inaccurate. For cloud assessments, I recommend pairing Canelo with a dedicated cloud security posture tool like Prowler or ScoutSuite. Those tools understand cloud metadata and IAM configurations in ways that a general network scanner cannot. Canelo is better suited for on-premises infrastructure and traditional network perimeters. Using it against containerized workloads without understanding the underlying orchestration layer produces noisy and often misleading results. The vulnerability database also updates on a schedule rather than in real time. If a new CVE drops on a Tuesday, Canelo will not have it until the next database sync, which may be days away. During that window, you are flying blind on anything related to that vulnerability. Check the release notes and update the database before every engagement. The update command is straightforward:

canelo update-db This process usually takes two to five minutes depending on your internet connection. Running it before every scan session is worth the minimal time investment.
Advanced Configuration Tips
The configuration file lives at ~/.canelo/config.yml and controls defaults for scan timing, module selection, and output formatting. Editing this file saves you from repeating the same flags on every command. I adjust the default scan rate to --rate 50 on slow networks to prevent overwhelming fragile services. On high-latency connections, the default rate causes timeout cascades that corrupt results. Lowering the rate stabilizes the output significantly. Another useful setting is the retry_count parameter. By default, Canelo retries failed probes three times. Increasing this to five helps in environments with packet loss, though it extends scan duration. The tradeoff is usually worth it for critical assessments where completeness matters more than speed. I keep retry_count at five for all production environment scans and drop it to three for lab testing. Module filtering is another area where Canelo shines if you use it correctly. You can disable entire module groups to speed up scans or reduce noise. For example, if you already know the web server technology from earlier reconnaissance, you can skip the web fingerprinting module and save scan time. The command looks like this:
canelo scan --target 10.0.0.0/24 --profile standard --skip-modules webfinger,snmp This kind of targeted skipping is where experience with the tool pays off. Beginners tend to run every module because the default profile includes them all. That is fine for initial discovery but wasteful once you have narrowed your focus. Use Canelo iteratively rather than as a one-shot tool. Initial broad scan for discovery, followed by targeted scans with modules disabled based on what you learned.

Getting Canelo
The tool is available on GitHub under the Sapiens AI organization repository. You can clone it directly or install via pip from the packaged release. The pip installation path is cleaner for most users because it handles dependencies automatically: pip install canelo-scanner If you need the latest development version with unreleased fixes, clone the repository and install from source. This is useful when you encounter a bug that has already been patched upstream but not yet shipped in a release. The GitHub URL is straightforward and well documented. Community support through the project issues page is active, and most common problems have resolved threads within a day or two.
Canelo is functional, covers the basics well, and has enough depth for serious assessments when you understand its limitations. It will not replace a full security toolkit, but it fills a specific niche for fast network reconnaissance that many testers find indispensable. Run it carefully, verify the results, and you will save considerable time compared to manual scanning workflows.