logoalt Hacker News

Snitch – A friendlier ss/netstat

193 pointsby karol-brodatoday at 1:03 AM43 commentsview on HN

Comments

mikeryantoday at 3:12 AM

When I saw this headline I assumed it was Little Snitch an existing network monitor and firewall for Macs.

Might need a different name.

https://www.obdev.at/products/littlesnitch/index.html

show 4 replies
PunchyHamstertoday at 7:51 AM

it's weird that both lsof and ss defaults are so awful

Like, ss without any options shows such arcane, rarely needed details as send/receive queue size but not the application socket belongs to.

And omits listening sockets which is main use for such tools.

I know picking the right defaults is hard ask but they managed to pick all the wrong defaults.

show 1 reply
fulafeltoday at 4:26 AM

The demo recording-as-code seems cool (in https://github.com/karol-broda/snitch/tree/master/demo)

themafiatoday at 2:38 AM

It looks nice, and I don't see anything wrong with it, but I've been using iptraf-ng since forever and I think it has a slight edge here.

Is it possible I've missed something from the demonstration video on that page?

show 1 reply
aostoday at 4:51 AM

I love the recent increase in TUI-based tooling. This looks cool - will check it out!

show 1 reply
poemxotoday at 6:54 AM

I don't like the name but I like the TUI, connection monitoring is perfectly handled by a TUI!

coppsilgoldtoday at 2:21 AM

I always wondered how useful such tools are against a competent adversary. If you are a competent engineer designing malware, wouldn't you introduce a dormancy period into your malware executable and if possible only talk to C&C while the user is doing something that talks to other endpoints? Maybe even choose the communication protocol based on what the user is doing to blend in even better.

show 3 replies
wittjefftoday at 7:24 AM

I can't read as fast as your demo GIF. Just infuriating.

cyberaxtoday at 3:22 AM

Nice! Couple of notes:

1. Can you highlight the currently selected row with a different background?

2. Maybe add optional reverse DNS lookups?

andrewmcwatterstoday at 4:08 AM

[dead]

stressbacktoday at 6:36 AM

prettyneat.gif

Thanks for sharing

rockskontoday at 5:22 AM

I just want a single tool that has a known, generalized set of capabilities on just about every distribution.

Systemd's obsession with remaking every single wheel in Linux has been aggravating enough. Please don't do it again.

show 3 replies