Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/aixisstudio/snitch
Defensive ToolsPacket Sniffing & AnalysisNetwork MappingInformation GatheringNetwork SecurityPrivacyDNS AnalysisAnomaly DetectionLog Analysis
GitHubaixisstudio/snitch

Snitch

Real-time network traffic visualizer — see every connection your computer makes. Privacy-first, 100% local. / Visualiseur de trafic réseau en temps réel, 100% local.

63431 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View RepositoryWebsite
Share

Snitch

Track every hidden flow. / Traquez chaque flux masqué.

English | Français

⭐ If Snitch helps you, a star means a lot! / Si Snitch vous aide, une étoile compte beaucoup ! ⭐

License: AGPL v3 Platform: macOS Platform: Windows Platform: Linux Version GitHub release Downloads GitHub stars

Snitch live graph — LAN perimeter, geolocated hosts, alerts


English

Snitch is a real-time network traffic visualizer. See every connection your computer makes — who it talks to, where they are, and which app is responsible.

The entire interface is available in English and French: use the EN / FR toggle in the top-right toolbar.

Why Snitch?

  • vs Little Snitch / Lulu — those are macOS firewalls that block connections; Snitch visualizes and explains traffic, is cross-platform, free and open-source.
  • vs GlassWire — Snitch is free, open-source (AGPL), requires no account and makes zero outbound calls; even geolocation is offline.
  • vs Wireshark — Snitch gives a live, high-level overview anyone can read, instead of raw packet dissection.
  • vs cloud-based monitors — everything runs on 127.0.0.1 behind a token; your traffic data never leaves the machine.

Features

FeatureDescription
Force GraphLive node graph — your machine at the center, every connection as a node
World MapGeolocated IPs with animated arcs on an interactive globe
15/30/60-min TimelineSliding history stored locally in SQLite (24 h retention)
Anomaly DetectionFlags port scans, beaconing, potential exfiltration
Process AttributionKnow which app generates which traffic (top 5 per connection)
LAN ScannerPassive discovery via the system ARP table (no broadcast scans)
Privacy ScoreReal-time score of your outgoing traffic exposure
Per-app ViewPer-process destinations, volumes and 60-min history
Alert SuppressionPersisted "ignore host/type" rules, manageable in the UI
Settings PanelLanguage, retention, filters, consent-gated GeoIP download, diagnostics
Tracker DetectionSuffix-matched domain lists shipped as editable data files (backend/classifier/lists/)
Bandwidth MonitorLive MB/s sparkline
EN / FR UIFull bilingual interface, one click to switch

Download

PlatformPackage
macOS (Apple Silicon)brew install --cask aixisstudio/tap/snitch — or Snitch-1.0.4-macos-arm64.zip
Linuxsudo docker compose up --build — see Docker (Linux)
WindowsBuild from source — see Build the installer

Or grab the latest release: github.com/aixisstudio/Snitch/releases

macOS first run / Premier lancement macOS — Snitch is ad-hoc signed, not notarized (no paid Apple Developer ID). The brew install --cask above removes the quarantine flag for you. For the manual zip: right-click → Open, or run xattr -dr com.apple.quarantine /Applications/Snitch.app. On first launch Snitch asks for your admin password once — packet capture requires it, same as tcpdump/Wireshark; the UI itself stays unprivileged.

FR — Snitch est signé ad-hoc, pas notarisé (pas de Developer ID payant). Le brew install --cask ci-dessus retire le drapeau de quarantaine pour vous. Pour le zip manuel : clic droit → Ouvrir, ou xattr -dr com.apple.quarantine /Applications/Snitch.app. Au premier lancement, Snitch demande le mot de passe admin une fois — la capture de paquets l'exige, comme tcpdump/Wireshark ; l'UI reste non privilégiée.

Stack

LayerTechnology
Packet capturectypes → libpcap — Npcap (Windows) / libpcap (Linux/macOS) — own parser (IPv4/IPv6/TCP/UDP/DNS/TLS-SNI)
Backend APIFastAPI — WebSockets — SQLite
FrontendReact 18 — Vite — D3.js v7 — TopoJSON
Desktop wrapperElectron 44
GeolocationOffline only — DB-IP Lite (CC BY 4.0) bundled gzip'd in backend/data/geo/, decompressed on first run; MaxMind GeoLite2 .mmdb also supported

Security & privacy

Download Tool