The definition of stealthy is bounded to who is monitoring the network.
In general, you can use ARP ping
using some automated tool like nmap
. It's more faster and reliable than normal IP ping scan.
can you exploit the ARP protocol in order to scan stealthily?
Normally, ARP activity on LAN is legit, but if you were intense and aggressive in your scan, you might be noticed.
Would an arp scan be picked up as suspicious activity?
No, but as I said, only if the admin hasn't noticed. For example, if you want to stay stealthy, try to automate the scan with long time periods.
Could you spoof the source address of ARP requests to remain stealthy?
If you spoofed the MAC to some random one, you might be stealthy, but the scan activity will still be noticeable, and you may rise a suspension.
In the end, my only advise is to stay stealthy by lowering time spaces between ARP pings.