picosnitch

picosnitch

Per-executable network monitoring for Linux

Description

On Linux, knowing which program phones home and how much bandwidth each app uses is hard when tools only show ports and IPs. picosnitch uses eBPF to break down and log network traffic per executable, notifying you when a new program connects or one is modified.

Bandwidth can be grouped by executable, hash, parent, domain, port or user, with web and terminal interfaces, GeoIP lookups and optional VirusTotal checks.

Features



Connection alerts:New or modified programs.

Traffic breakdown:By program, domain, port or user.

GeoIP:Location for each connection.

Optional scanning:VirusTotal hash checks.