Tuesday, October 6, 2026

Snitch for real-time local network traffic visualization

Snitch for real-time local network traffic visualization

Snitch is a free, cross-platform, fully local visualizer that shows every connection your machine makes, who it talks to, where hosts are, and which process is responsible.

Toolaixisstudio/Snitch — real-time network traffic visualizer with process attribution, anomaly detection and offline geolocation
CategoryNetwork monitoring / traffic visualization (Python FastAPI, libpcap, React, D3.js, Electron)
Primary UseUnderstanding and auditing your own machine's outbound connections — live force graph, world map, per-app history and anomaly alerts in snitch.db
Safe UseDesigned for defensive self-monitoring on hosts you own or administer; useful to authorized security teams reviewing endpoint egress behavior and privacy exposure
Telemetry NotePassive observation only — no broadcast scans, zero outbound calls except opt-in GeoIP download; leaves snitch.db and data/logs/snitch.log locally, visible via GET /diagnostics

Most endpoint egress tooling forces a choice between packet-level depth and human readability. aixisstudio/Snitch, currently at version 1.0.4 with 71 stars and an AGPL-3.0 license, positions itself precisely in that gap: a real-time visualizer that shows every connection your machine makes, who it talks to, where the remote hosts sit geographically, and — the hard part — which application is responsible. The README is refreshingly candid about where the project sits relative to established tools: unlike Little Snitch or LuLu, which are macOS firewalls that block connections, Snitch visualizes and explains traffic; unlike Wireshark, it trades raw packet dissection for a live, high-level overview; and unlike GlassWire, it is free, requires no account, and makes zero outbound calls.

The architecture is a clean three-layer split. A Python backend does packet capture via ctypes bindings straight into libpcap — Npcap on Windows, plain libpcap on Linux and macOS — using the project's own parser covering IPv4, IPv6, TCP, UDP, DNS and TLS-SNI. That last detail matters: pulling the Server Name Indication field out of TLS handshakes is how the tool associates encrypted connections with readable hostnames without decrypting anything. The capture engine feeds a FastAPI service exposing WebSockets and SQLite persistence, while the frontend is React 18 with Vite, rendering the force graph and animated world-map arcs with D3.js v7 and TopoJSON, all wrapped in an Electron 44 desktop shell.

The feature set reads like an analyst's wish list for endpoint egress monitoring. The force graph puts your machine at the center with every connection as a node; the world map geolocates remote IPs with animated arcs; a sliding 15/30/60-minute timeline is backed by per-minute per-host and per-process byte and packet aggregates in SQLite (host_history, process_history) with a 24-hour retention window configurable via retention_hours. Anomaly detection flags port scans, beaconing behavior, and potential exfiltration — the classic C2-communication patterns that defenders care about — while a real-time privacy score summarizes your outgoing traffic exposure.

Process attribution is where most lightweight monitors fall over, and Snitch handles it by reporting the top five processes per connection. The per-app view then breaks down each process's destinations, volumes and 60-minute history. There is also tracker detection built on suffix-matched domain lists shipped as editable data files under backend/classifier/lists/, meaning the classification logic is auditable and extensible rather than opaque. A bandwidth monitor renders a live MB/s sparkline for quick sanity checks on unexpected volume spikes.

The privacy engineering deserves specific attention because it is unusually thorough for this category. Everything runs on 127.0.0.1 behind an API token: Electron generates the token per launch, while in Docker or browser mode it is printed once in backend logs and stored in data/api_token.txt, with the UI opened as http://localhost:8000/?token=<TOKEN>. CORS and WebSocket origin allowlists restrict connections to localhost:5173, the backend's own origin, and Electron's file:// pages. Geolocation is strictly offline — DB-IP Lite (CC BY 4.0) ships gzip-compressed in backend/data/geo/ and is decompressed on first run, and the tool also accepts MaxMind GeoLite2-City.mmdb or GeoLite2-Country.mmdb-style databases dropped into the data directory. The only possible outbound call is the consent-gated DB-IP Lite refresh in Settings.

LAN visibility is achieved without active scanning, which is a design decision worth respecting. The LAN scanner works passively off the system ARP table — no broadcast probes — and enriches device names from what hosts already announce about themselves: mDNS *.local names on Apple and Linux, LLMNR and NetBIOS names on Windows, DHCP hostname options, plus the bundled offline IEEE OUI vendor table. The gateway is auto-detected as the router. For anyone who has watched noisy discovery tools trip IDS rules on a monitored segment, this passive posture is the right call.

Deployment options cover the three major platforms asymmetrically. macOS Apple Silicon gets the easiest path with brew install --cask aixisstudio/tap/snitch or a release zip; note the binary is ad-hoc signed and not notarized, so the manual zip route requires right-click-to-open or xattr -dr com.apple.quarantine /Applications/Snitch.app. Linux runs via sudo docker compose up --build, where packet capture works through network_mode: host so the container sees real host traffic — but with the documented limitation that process attribution is restricted to container processes, and Docker Desktop on Mac or Windows cannot see host traffic from inside its VM. Windows users build from source.

Privilege handling follows the same pattern as tcpdump and Wireshark: raw packet capture requires admin, so Snitch asks for the administrator password once on first launch while the UI itself stays unprivileged. The Docker variant similarly needs root for raw socket access. This is standard for anything touching libpcap, but reviewers should note the implication for hardened endpoints — deployment belongs in a change-managed context on machines you administer.

The API surface is well thought out for scripting and triage. Beyond the WebSocket stream, GET /history/host/{ip} and GET /history/process/{name} pull the retention-window aggregates, POST /alerts/ignore, DELETE /alerts/ignore and GET /alerts/ignore manage alert suppression rules persisted in the alert_suppressions table and applied before alerts are emitted, and GET /diagnostics returns a secrets-free JSON snapshot of capture state, geo database status, interface, versions and paths. Alert fatigue is the predictable failure mode of any anomaly monitor, and persisted per-host and per-type suppression that survives restarts is the correct mitigation.

For evaluation and training purposes the project ships a demo mode: running the backend with SNITCH_DEMO=1 feeds synthetic traffic through the real pipeline with no root, no libpcap, and no real packets touched. That is a genuinely useful touch for lab environments, screenshots, and CI — the demo capture on the repo front page is generated this way. The backend test suite runs with python -m pytest tests/ -v and the frontend with npm test, and a documented threat model lives at docs/threat-model.md, which is more documentation discipline than most tools in this space offer.

Within an authorized workflow, Snitch slots in as an endpoint egress audit and privacy-exposure tool: verifying which applications phone home, spotting beaconing or scan patterns from a workstation you control, and building a defensible record of per-process network behavior in snitch.db. It is not an IDS, not a firewall, and does not pretend to be — it is the explanatory layer that sits above packet capture. For professionals who want to answer "what is this machine talking to and why" in sixty seconds without reading a pcap, the AGPL-licensed, zero-telemetry, loopback-only design makes it one of the more trustworthy options to evaluate.

Official project repository for aixisstudio/Snitch.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.