Skip to content
domcyrusPublic

About

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Topics

Resources

Contributing

Security policy

Stars

5.1k stars

Watchers

32 watching

Forks

Latest commit

 

History

788 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

RustNet

Built with Ratatui Build status Crates.io version Latest release Packaging status Apache 2.0 license

English | 简体中文 | 日本語

RustNet is a terminal network monitor that shows live TCP, UDP, and QUIC connections with process attribution when available. It runs on Linux, macOS, Windows, and FreeBSD.

Install

On macOS or Linux with Homebrew:

brew install rustnet

Packet capture needs platform-specific permissions. See the installation guide for Linux capabilities, macOS PKTAP and BPF access, other package managers, and troubleshooting.

Release status: The highlights, GIF, and screenshots show v1.7.0. The recordings use generated traffic in an isolated Linux environment. The guides linked from main may also describe unreleased changes. For the installed release, use the v1.7.0 documentation and check rustnet --version and rustnet --help.

Demo

RustNet demo

Highlights

  • Shows connection state, traffic, application protocol, and available process information in a terminal UI that works over SSH.
  • Identifies protocols such as HTTP, TLS/SNI, DNS, SSH, and QUIC through packet inspection.
  • Filters connections by process, address, port, protocol, and more.
  • Streams versioned JSON snapshots in headless mode for scripts and monitoring.
  • Shows host sockets, passive DNS analytics, and connection health.
  • Exports captures as PCAP or PCAPNG with best-effort annotations for analysis in Wireshark.
  • Reduces privileges after startup and uses platform sandboxing where supported.

See the usage guide, architecture guide, and security guide for feature details.

Since v1.7.0, RustNet requires trusted directories for Unix output files and creates diagnostic logs exclusively.

v1.7.0 fixes ARM DEB compatibility with older glibc and Debian 13's time64 libraries. See the installation guide for supported distributions; v1.6.0 assets do not include these fixes.

Screenshots

Overview
Live connections and traffic
RustNet Overview
Details
Process, protocol, and peer information
RustNet Details
Graph
Traffic and application charts
RustNet Graph
Activity
Traffic by process
RustNet Activity
Host sockets
Listening and bound endpoints
RustNet Host sockets
DNS
Passive DNS queries and responses
RustNet DNS

Other installation methods

Platform Command
Ubuntu 22.04+ / Linux Mint 21+ sudo add-apt-repository ppa:domcyrus/rustnet
sudo apt update && sudo apt install rustnet
Fedora 42+ sudo dnf copr enable domcyrus/rustnet
sudo dnf install rustnet
Arch Linux sudo pacman -S rustnet
Alpine Linux (edge/community) apk add rustnet
Windows choco install rustnet or scoop install rustnet
Cargo cargo install rustnet-monitor
Nix / NixOS nix-shell -p rustnet

Windows also requires Npcap. v1.7.0 supports its default settings; v1.6.0 requires "WinPcap API compatible mode". For openSUSE, Pop!_OS, FreeBSD, Docker, and source builds, see the installation guide.

Run

On Linux, after configuring capabilities:

rustnet

On macOS, PKTAP requires sudo. With BPF access configured, RustNet can run without it but uses lsof for process detection.

Press / to filter connections, Enter to inspect one, and q to quit. See the usage guide for interface selection, options, controls, filters, and exports.

Documentation

The rustnet binary is the supported product. Workspace crate APIs are internal and may change without compatibility shims.

RustNet uses ratatui for its terminal UI and libpcap/Npcap for packet capture. See CONTRIBUTORS.md for project contributors.

Licensed under Apache License 2.0.

About

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Topics

Resources

Contributing

Security policy

Stars

5.1k stars

Watchers

32 watching

Forks

Releases

Packages

Used by

Contributors

Languages