Who is your computer talking to right now?
Not a rhetorical question. While you read this, your machine is probably holding dozens of open connections — sync services, CDNs, telemetry endpoints, ads, things you installed three years ago and forgot about. I wanted to see them. Not in a terminal dump, but as a living picture.
So I built Snitch: a free, open-source, 100% local network traffic visualizer.
What it does
Snitch captures outbound traffic in real time and renders it as an animated node graph plus a world map:
- Live node graph — every remote host your machine touches, glowing and moving
- World map — geolocation of every endpoint, fully offline (MaxMind GeoLite2, no API calls)
- Per-process attribution — not just "some connection to 142.250.x.x" but which app opened it
- Anomaly detection — port scans, beaconing patterns, suspicious exfiltration volumes
- Privacy score — a live rating of how chatty your system is, broken down by trackers/CDNs/normal traffic
- Bilingual UI — English and French, switchable at runtime
Why another tool?
- Little Snitch / Lulu — macOS-only (Lulu is free, Little Snitch is paid), firewall-centric
- GlassWire — Windows-centric, freemium, phones home
- Wireshark — the gold standard, but it's a protocol analyzer, not a dashboard; way too heavy to leave running
Snitch sits in the gap: an always-on, glanceable, local-first monitor. The capture is passive (libpcap), the analysis happens on your machine, and nothing — literally nothing — leaves your computer. The API binds to 127.0.0.1 with a bearer token, and there are zero outbound requests by design. It's in the threat model, not just the marketing.
Some engineering choices
- Own packet parser instead of Scapy — Scapy is GPL-incompatible with the license I wanted, so I wrote a minimal L2/L3/L4 decoder. Less code than integrating it.
- Offline GeoIP — a bundled database beats a "free API" that dies in two years and leaks your traffic metadata to a third party.
-
Electron + React + FastAPI — desktop app, but the backend runs standalone too (
uvicorn+ any browser). -
Demo mode —
SNITCH_DEMO=1injects synthetic traffic through the real pipeline so you can try it without root/pcap.
Try it
git clone https://github.com/aixisstudio/Snitch
# or one-click install via Pinokio, or Docker, or the Electron builds
Repo: https://github.com/aixisstudio/Snitch — AGPL-3.0. Stars, issues, and PRs welcome. There are a few good first issue tickets open if you want to get involved.
Curious what you'd find on your own machine. Honest feedback welcome — especially on the anomaly heuristics.

Top comments (0)