{"repo":"domcyrus/rustnet","free":true,"listed":false,"github":"https://github.com/domcyrus/rustnet","clone":"git clone https://github.com/domcyrus/rustnet.git","description":"Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.","language":"Rust","stars":4862,"topics":["ebpf","freebsd","geoip","landlock","linux","network-monitoring","packet-capture","rust","seatbelt","tui"],"license":"Apache-2.0","category":"cli-tools","readme_excerpt":"RustNet Per-process network monitoring for your terminal: live TCP, UDP, and QUIC connections with deep packet inspection, sandboxed by default. English 简体中文 日本語 Real-time visibility into every connection your machine makes, who owns it, and what protocol it's speaking. No tcpdump, X11 forwarding, or root piping. Features - Per-process attribution : Every TCP, UDP, and QUIC connection mapped to its owning process, via eBPF on Linux, PKTAP on macOS, ETW with an automatic IP Helper fallback on Windows, and native APIs on FreeBSD. Details include PID, executable, user/group names, match confidence, and a capped parent-process chain on every platform. Wireshark and tcpdump can't do this; netstat / ss can't show live state. - Deep packet inspection : Identify HTTP, HTTPS/TLS with SNI, DNS, SSH, FTP, QUIC, MQTT, BitTorrent, STUN, NTP, mDNS, LLMNR, DHCP, SNMP, SSDP, and NetBIOS, without external dissectors. - Annotated PCAPNG export : --pcapng-export writes a Wireshark-ready capture with process, PID, direction, DPI/SNI, and GeoIP embedded as per-packet comments. Open it in Wireshark and every packet already names its owning process, with no post-processing. Classic --pcap-export with a JSONL sidecar for offline correlation is also available. - Security sandboxing : Landlock (Linux 5.13+), Seatbelt (macOS), token privilege drop + job-object child-process block (Windows). Drops privileges immediately after libpcap initializes. See SECURITY.md. - Network analytics : Real-time round-tr","default_branch":null,"files":null,"tree":[],"storefront":"/r/domcyrus","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/domcyrus/rustnet/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}