Your Mac makes hundreds of outbound connections every hour — updaters, analytics SDKs, crash reporters, CDNs. None of it is visible unless you go looking. lsof -i gives you a wall of IPs. Little Snitch gives you prompts, a firewall, and a €59 price tag.
We wanted something in between: see everything, block nothing, send nothing. So we built Snitch — an open-source, local-first network traffic visualizer for macOS.
What it does
- Live graph of every outbound connection, grouped by process
- World map plotting destination IPs — resolved from a bundled GeoIP database, fully offline
- Per-app breakdown: bytes in/out, destinations, first-seen vs recurring
- Anomaly alerts when a process reaches a destination it has never touched before
- Demo mode — explore the full UI with synthetic data, no root required
The part we're most proud of: the privacy model
A network monitor that phones home would be a joke, so we designed around it:
- The API binds to
127.0.0.1only. Nothing listens on a routable interface. - Every endpoint — REST and WebSocket — requires a random token generated per install.
- GeoIP lookup happens against a bundled database. No destination IP ever leaves the machine.
- No analytics, no crash reporters, no update pings. Snitch makes zero outbound connections itself.
If you watch Snitch with Snitch, you see silence. That's the demo we care about.
How it works
The backend is Python + FastAPI. Per-process attribution comes from polling nettop/lsof rather than a kernel extension — that keeps the app usable without SIP gymnastics and makes the unsigned build tolerable. Connections stream to the React frontend over a token-authenticated WebSocket, rendered as a force-directed graph plus an SVG world map.
The honest trade-off: polling instead of a Network Extension means Snitch visualizes but doesn't block. If you want per-app blocking, pair it with LuLu — they complement each other well.
Current state
- macOS build is unsigned for now — right-click → Open, or build from source in ~2 minutes
- Windows/Linux builds are on the roadmap (the backend already runs cross-platform)
- 4
good first issuetickets open if you want to contribute
Links: GitHub · Releases · Wiki · r/SnitchApp
Disclosure: we're aiXis Studio, the studio behind Snitch. The project is AGPL-3.0 and free forever. French version of the docs included — la doc est bilingue.
If it helps you see what your machine is up to, a star on the repo means a lot — and feedback means even more.
Who is your computer talking to right now?
Not a rhetorical question. While you read this, your machine is probably holding dozens of open connections — sync services, CDNs, telemetry endpoints, ads, things you installed three years ago and forgot about. I wanted to see them. Not in a terminal dump, but as a living picture.
So I built Snitch: a free, open-source, 100% local network traffic visualizer.
What it does
Snitch captures outbound traffic in real time and renders it as an animated node graph plus a world map:
- Live node graph — every remote host your machine touches, glowing and moving
- World map — geolocation of every endpoint, fully offline (MaxMind GeoLite2, no API calls)
- Per-process attribution — not just "some connection to 142.250.x.x" but which app opened it
- Anomaly detection — port scans, beaconing patterns, suspicious exfiltration volumes
- Privacy score — a live rating of how chatty your system is, broken down by trackers/CDNs/normal traffic
- Bilingual UI — English and French, switchable at runtime
Why another tool?
- Little Snitch / Lulu — macOS-only (Lulu is free, Little Snitch is paid), firewall-centric
- GlassWire — Windows-centric, freemium, phones home
- Wireshark — the gold standard, but it's a protocol analyzer, not a dashboard; way too heavy to leave running
Snitch sits in the gap: an always-on, glanceable, local-first monitor. The capture is passive (libpcap), the analysis happens on your machine, and nothing — literally nothing — leaves your computer. The API binds to 127.0.0.1 with a bearer token, and there are zero outbound requests by design. It's in the threat model, not just the marketing.
Some engineering choices
- Own packet parser instead of Scapy — Scapy is GPL-incompatible with the license I wanted, so I wrote a minimal L2/L3/L4 decoder. Less code than integrating it.
- Offline GeoIP — a bundled database beats a "free API" that dies in two years and leaks your traffic metadata to a third party.
-
Electron + React + FastAPI — desktop app, but the backend runs standalone too (
uvicorn+ any browser). -
Demo mode —
SNITCH_DEMO=1injects synthetic traffic through the real pipeline so you can try it without root/pcap.
Try it
git clone https://github.com/aixisstudio/Snitch
# or one-click install via Pinokio, or Docker, or the Electron builds
Repo: https://github.com/aixisstudio/Snitch — AGPL-3.0. Stars, issues, and PRs welcome. There are a few good first issue tickets open if you want to get involved.
Curious what you'd find on your own machine. Honest feedback welcome — especially on the anomaly heuristics.

Top comments (0)