WiFi X-Ray

A Fifteen Minute Home Network Audit

In short

A useful home network audit takes about fifteen minutes when it focuses on four things: the devices connected now, Wi-Fi encryption, router administration, and obvious exposure. The goal is to establish a reliable baseline and make a short list of changes, not to prove that a network is free of every possible threat.

Key takeaways

  • A device inventory is the foundation of a home network audit because unknown names need context before they become a security finding.
  • WPA3 or WPA2 with a strong unique passphrase is preferable to obsolete or open Wi-Fi security modes.
  • Router firmware and administrator credentials should be reviewed separately from the Wi-Fi password.
  • A short audit should record follow-up tasks instead of making disruptive changes without checking device dependencies.

A useful home network audit takes about fifteen minutes when it focuses on connected devices, Wi-Fi encryption, router administration, and obvious exposure. The aim is a dependable baseline and a short list of fixes, not a claim that the network is immune to every threat.

What should you prepare before starting?

Have access to the router’s administration interface and a way to note findings. This can be a simple paper list or a private note. Do not record passwords in a shared document. If someone else manages the internet service, involve them before changing router settings.

Disconnecting a device just to make a list can create confusion, particularly for security cameras, medical-adjacent equipment, or home automation. The first pass should be observational. You can make a change later, after you know what it affects.

TimeTaskOutcome
0–4 minutesList connected devicesA baseline of expected and unfamiliar clients
4–7 minutesCheck Wi-Fi securityEncryption mode and passphrase review
7–11 minutesReview router accessFirmware, administrator access, remote management
11–15 minutesReview exposure and record actionsA prioritised follow-up list

How do you inventory devices in four minutes?

Open the router’s connected-device page or use a local network scanner. Record each entry’s name, IP address, and any recognisable type. Look for the devices people forget: televisions, streaming boxes, printers, speakers, thermostats, cameras, plugs, bridges, and old phones.

An unknown entry is not automatically malicious. Private or randomized MAC addresses can make a phone appear differently over time, and many products advertise generic hostnames. Cross-check the list by turning a known device off briefly, checking its own network settings, or looking for a manufacturer-provided name.

WiFi X-Ray can build this inventory with local discovery, Bonjour naming, and device fingerprinting, then retain labels you add across scans. Its result is still an inventory to investigate, not evidence of an intrusion.

Which Wi-Fi settings deserve attention?

Find the security mode for each active Wi-Fi network, including guest networks. Prefer WPA3 where your equipment supports it, or WPA2 with AES-based protection for older compatible equipment. Replace open networks, WEP, and legacy WPA modes. Use a unique passphrase that is long enough to resist guessing and that is not reused for another service.

Check whether an old network name remains enabled for compatibility. A forgotten legacy SSID can undermine the policy you intended for the main network. If older devices require a different setting, place them on a separate network when your router supports it, and plan replacement rather than quietly leaving an insecure mode enabled forever.

Do not confuse hiding an SSID with securing it. A hidden name does not prevent capable devices from discovering the network. Encryption and a strong passphrase provide the meaningful access control.

What should you check in the router in four minutes?

First, check firmware status. Apply vendor-provided updates through the normal administration interface, ideally during a time when a restart will not disrupt important activity. Then confirm that the router administrator password is unique and not the printed default. This password controls the network, while the Wi-Fi passphrase controls joining it; both matter.

Review remote administration. Turn it off unless you have a clear, documented reason to use it. If you need remote access, use the router vendor’s supported secure method, strong account protection, and the narrowest available access policy. Do not expose an administration page to the internet casually.

Finally, look at the DNS setting. It should be one you recognise, whether supplied automatically by your provider or deliberately configured. An unfamiliar manual DNS setting deserves investigation, especially after a router reset or a change you did not make.

Should you review UPnP and port forwarding?

Yes, but with care. UPnP, Universal Plug and Play, lets devices ask the router to create port mappings automatically. It can be useful for games, media services, and some communication tools. It also means a device on your network may request an externally reachable mapping, so it should be a conscious choice rather than an unexamined default.

List existing manual port forwards. For each one, write the destination device, port, protocol, and reason. Remove forwards for equipment you no longer own or services you no longer use. If something breaks after changing UPnP, restore only the specific required arrangement after understanding it.

A focused gateway audit can indicate whether the router advertises UPnP or accepts plaintext Telnet or FTP on the local gateway. It does not detect attackers or scan the internet. WiFi X-Ray presents these observations as part of a local security posture grade and offers router-specific remediation steps for supported brands.

What should you do with the results?

Make a small action list with an owner and a time. Prioritise known weak encryption, default administrator credentials, disabled updates, and unneeded remote administration. Then address mystery devices through identification, not assumption. If a device remains unrecognised after reasonable checks, change the Wi-Fi passphrase, reconnect trusted devices deliberately, and monitor the new inventory.

Repeat the short audit after adding a major smart-home product or replacing the router. A baseline becomes valuable only when you maintain it. The check is successful when you understand what is connected, how access is controlled, and which exceptions remain.

How often should I audit a home network?

A brief review every few months and after adding major devices is practical. Review sooner after a router reset, suspected account compromise, or a remote-access change.

Is an unknown device always an intruder?

No. It may be a phone using a private address, a printer, or a smart appliance with a generic name. Identify it with timing, labels, and physical checks before changing access.

Should I turn off UPnP immediately?

UPnP can help games, media devices, and calls create required connections. Review whether it is needed and test dependent devices after changing it.

Frequently asked questions

How often should I audit a home network?

A brief review every few months and after adding major devices is a practical routine. Review sooner after a router reset, suspected account compromise, or a change to remote access.

Is an unknown device always an intruder?

No. It may be a phone using a private address, a printer, a smart appliance, or a device with a generic hostname. Identify it through timing, names, and physical checks before changing access.

Should I turn off UPnP immediately?

UPnP can help games, media devices, and calls create required connections. Review whether it is needed and test dependent devices after changing it.