8 ms·
Snitch – A friendlier ss/netstat
- deleted 9mo ago[deleted]
- coppsilgold 9mo agoI always wondered how useful such tools are against a competent adversary. If you are a competent engineer designing malware, wouldn't you introduce a dormancy period into your malware executable and if possible only talk to C&C while the user is doing something that talks to other endpoints? Maybe even choose the communication protocol based on what the user is doing to blend in even better.
- tptacek 9mo agoTools like these aren't really intended for adversarial environments, and pure network tools that are designed for real adversaries have a really spotty track record (good search: [bro vantage point problem]).
- entrop 9mo agoThat search did not come up with much. Can you elaborate?
- alwa 9mo agoNot tptacek, but my search yielded this which seems relevant (to the network monitoring tool once named Bro, now Zeek): https://www.icir.org/mallman/pubs/APT07/APT07.pdf https://www.icir.org/mallman/pubs/APT07/APT07.pdf > The “SH” state indicates that the remote peer sent a SYN followed by a FIN—however, the monitor never recorded a SYN-ACK from the local peer. At first glance, this would seem to indicate a scanner that is trying to make connection attempts look as real as possible in the hopes of not triggering an alarm. However, such connections can also indicate a vantage point problem whereby the monitor is not observing outgoing traffic from some hosts. While in general the monitor placement at LBNL can observe both incoming and outgoing traffic, there were periods of time where the traffic for some LBNL hosts would partially bypass the monitor. From a measurement perspective this is clearly undesirable.
- karol-broda 9mo agoagreed on the limits. snitch isnt aimed at adversarial detection; its a local debugging/inspection tool. a competent attacker can blend in by design, so this isnt meant to be a standalone security control
- ashtakeaway 9mo agoWith a name like Snitch, it should be aimed at adversarial detection. Just my two snitches.
- gus_ 9mo agoAt the very least, these tools should not parse /proc to obtain information of processes or connections. It should be the last option. Many LD_PRELOAD rootkits hide their activity from the system by manipulating the output of libc functions like readdir(), open(), stat(), etc. kernel rootkits can hide whatever they need, but the common functionality is also to hide data from /proc. That's why netstat, ps, *top or lsof are not reliable tools if the system is compromised. ss is a bit different and is a bit more reliable. In this case, snitch is written in Go, which doesn't use the libc functions, so probably it'll be able to obtain information from /proc even if hidden by a LD_PRELOAD rootkit. Another option would be to compile the binary statically. Anyways, these tools are not meant to unhide malicious traffic or processes, so I think detecting beacons, inspecting traffic, etc, is out of the scope. Resources: https://github.com/gustavo-iniguez-goya/decloaker https://github.com/gustavo-iniguez-goya/decloaker User-space library rootkits revisited: Are user-space detection mechanisms futile? - https://arxiv.org https://arxiv.org html/2506.07827v1 The Hidden Threat: Analysis of Linux Rootkit Techniques and Limitations of Current Detection Tools - https://dl.acm.org/doi/10.1145/3688808 https://dl.acm.org/doi/10.1145/3688808 https://matheuzsecurity.github.io/hacking/bypass-userland-hooks/ https://matheuzsecurity.github.io/hacking/bypass-userland-ho... https://ops.tips/blog/how-is-proc-able-to-list-pids/ https://ops.tips/blog/how-is-proc-able-to-list-pids/
- jcgl 9mo agoWhat makes ss different? In any case, interesting to think of shared libraries (specifically shared libc) as a risk here. Makes sense, but I hadn't thought about it before. That said, I'm having a hard time doing a threat model where you worry about an attacker only setting LD_PRELOAD but not modifying PATH. The latter is more general and can screw you with all programs (doesn't cover shell builtins, but it's not like those would just be one more step).
- gus_ 9mo agoss obtains the connections information via netlink directly from the kernel (besides parsing /proc): https://manpages.debian.org/bookworm/manpages/sock_diag.7.en.html#IPv4_and_IPv6_sockets https://manpages.debian.org/bookworm/manpages/sock_diag.7.en... https://github.com/vishvananda/netlink/blob/main/inet_diag.go https://github.com/vishvananda/netlink/blob/main/inet_diag.g... Not many rootkits tamper the netlink channel, so in most cases it's a bit more reliable.
- themafia 9mo agoIt looks nice, and I don't see anything wrong with it, but I've been using iptraf-ng since forever and I think it has a slight edge here. Is it possible I've missed something from the demonstration video on that page?
- karol-broda 9mo agothanks! snitch is closer to an ss/netstat replacement (sockets + processes) than a traffic monitor. traffic monitoring is planned, but not implemented yet.
- mikeryan 9mo agoWhen I saw this headline I assumed it was Little Snitch an existing network monitor and firewall for Macs. Might need a different name. https://www.obdev.at/products/littlesnitch/index.html https://www.obdev.at/products/littlesnitch/index.html
- wkat4242 9mo agoThere's also a Linux clone of little snitch, OpenSnitch.
- zormal 9mo agoThere's also https://github.com/snitch-org/snitch https://github.com/snitch-org/snitch with the AUR package name 'snitch'.
- stressback 9mo agoSeems like a fine name. Why would little snitch existing necessitate a name change?
- charcircuit 9mo agoBecause it's potentially trademark infringement because it could confuse people.
- cyberax 9mo agoNice! Couple of notes: 1. Can you highlight the currently selected row with a different background? 2. Maybe add optional reverse DNS lookups?
- karol-broda 9mo agowas thinking of adding more customizable theming, like highlighting the background and reverse dns resolution was released earlier
- andrewmcwatters 9mo ago[dead]
- fulafel 9mo agoThe demo recording-as-code seems cool (in https://github.com/karol-broda/snitch/tree/master/demo https://github.com/karol-broda/snitch/tree/master/demo)
- karol-broda 9mo agothanks :), havent really seen this much in other projects
- aos 9mo agoI love the recent increase in TUI-based tooling. This looks cool - will check it out!
- mabedan 9mo agoAre they as accessible as GUI though (genuine question) UI libraries have a lot of features for allowing people with disabilities to “read” and interact with the screen in efficient ways
- 4gotunameagain 9mo agoAccessibility is a great thing to have and strive for, but it cannot be the number one design principle. Imagine if everything around us would be designed for blind people.
- austinjp 9mo agoI suspect blind people imagine that a lot. The idea is to design for all (or as many as feasible), it's not a binary either/or.
- 4gotunameagain 9mo agoYou cannot design a lot of TUI for all. Should we abandon TUI entirely ?
- TZubiri 9mo agoNot necessarily designed for, but accessible to. Additionally in sysadmin, blind-users are not just some random group, the ability not to use one's eyes is central to the Command Line Interface. You could always in theory get by with just a keyboard and a TTS that reads out the output, it's all based on the STDIO abstractions that are just string streams, completely compatible and accessible to blind, and even deaf users. (Unlike GUIs)
- WhyNotHugo 9mo agoTUI tools are generally as accessible as the terminal on which they run. GUI apps are much trickier. They require that the developer implement integration with accessibility frameworks (which vary depending on X11/Wayland) or use a toolkit which does this.
- rockskon 9mo agoI just want a single tool that has a known, generalized set of capabilities on just about every distribution. Systemd's obsession with remaking every single wheel in Linux has been aggravating enough. Please don't do it again.
- Underphil 9mo agoNo-one is stopping you from using netstat.
- beaudidly 9mo agoWhat’s with the hostility of someone making something that’s useful for themselves and sharing it with others?
- hn_throw2025 9mo agoIronic choice of example… Before systemd presented a generalised interface, there were significant differences in the init and service management systems between the popular Red Hat and Debian families of distros.
- rockskon 9mo agoNot what I meant. Systemd has been replacing a bunch of commands too. Not just the init system.
- jcgl 9mo agoThose additional programs can be freely chosen by distros and/or users. So each of them has to stand on their merit. Though of course they do get some built-in credibility by coming from the systemd project. But for the most part, I think systemd software just tends to have competitive offerings with nice interfaces.
- rockskon 9mo agoI'm annoyed at it replacing resolvconf. At reboot. At date. At logging. At cron. At ntpd. At network configuration scripts. Some of these I'm sure make life easier for maintainers. Others just feel like change for the sake of change. Breaking workflows because someone wanted to design a better wheel.
- stressback 9mo agoprettyneat.gif Thanks for sharing
- poemxo 9mo agoI don't like the name but I like the TUI, connection monitoring is perfectly handled by a TUI!
- karol-broda 9mo agothanks, but what don’t you like about the name?
- poemxo 9mo agoSorry for slow response. Snitch sounds like a tool that will do intercepting or alerting. Little Snitch is perfectly named in this regard. When it pops up prompting you for action, it feels like it just snitched on an app. What you have here isn't a snitch, it's more like a full map of traffic. I don't have any other suggestions unfortunately. Just my 2c
- wittjeff 9mo agoI can't read as fast as your demo GIF. Just infuriating.
- karol-broda 9mo agoit’s all code, if you want you can make a pr with adjustments to the demo
- PunchyHamster 9mo agoit's weird that both lsof and ss defaults are so awful Like, ss without any options shows such arcane, rarely needed details as send/receive queue size but not the application socket belongs to. And omits listening sockets which is main use for such tools. I know picking the right defaults is hard ask but they managed to pick all the wrong defaults.
- petepete 9mo agoI think the same applies for many of the new breed of command line applications like fd and ag/rg. Being able to use them intuitively trumps ubiquity, speed or features.
- mr_mitm 9mo agoDepends on the use case. If used in scripts, ubiquity and speed can be important. Then again, the output of ss is not ideal for script processing.
- PunchyHamster 9mo agoThat's the problem, it's not good for humans, it's not great for scripts
- PunchyHamster 9mo agoBut it's not tradeoff! You can make default view useful without trading versatility. Another annoying part is not supporting json or even CSV. Some tools got modernized with it (like iproute2 tool set), but for these you might as well do /proc scraping yourself...
- sureglymop 9mo agoThat's true in general. But default view is still subjective. The challenge probably lies in recognizing the larges subset of your user base that would like it to be a certain consistent way.
- 9mo ago
- TZubiri 9mo agoOne aspect of sysadminship that I find cute (but suboptimal) is how we memorize this strings of commands that were clearly not quite designed to be used in that manner. A slightly related example is how our intents in our mind end up having commands that don't resemble at all what we actually want, creating a map between intent and command that is almost exclusively arbitrary except for some obsucre etymological origin that might or might not help you remember the command in a time of need. For example: Intent: "create a file" Command: "touch $FILE" As it happens, touching a file doesn't mean to create, it was supposed to touch to modify the last access date, like a null op. But now if you want to create a file you do that. Intent: "Print a file contents to screen" Command: "cat $FILE" Is this a reference to a feline? some slang for printing or reading? No it's short for concatenate, but if you pass just one argument instead of 2, it prints the concatenation of 1 file and nothing. Even something as simple as Intent: "Rename a file" Command: "mv $FILE" Of ocurse there's the fact that moving a file and renaming the file are very similar if not identical in most FS/OS, but also, the slight change from a word to a proper-name style command already creates a style of command line interaction that was very natural in the 80s, but is now being reinvented with the advent of more powerful language decoding technology. So even: Intent: "Copy a file" Command: "cp $FILE" Now to the topic, you can see how my relationship with ss is the mapping: Intent: "See a list of open ports" Command: "ss -tulnp" Which I remember mnmemotecnically because it is close to -tulip. This is similar to ps -aux in that the command includes a set of options and I remember it mnemotecnically ("auxiliary" or "auxilio"), and I use the options even when I don't need them, modifying the options from that baseline if needed, like removing "a" to get just the current user's processes. That said. I don't know if the future is going to be "better" alternatives to old tools, but rather deconstructing or making use of the concept of "binary":"command", running man and --help has never been an optimal solution, and let's be honest, kids nowadays are googling, stackoverflowing and chatgpting their intent in order to get a magical command. No easy way to improve upon this at the userspace level, the OS model of delegating control to binaries based on a hierarchical command structure is sensible, and "magic", or sharing commands across binaries without a clear ruleset would be too opaque. But I feel that creating new tools while barely revolutionizing the way they work is too small an incremental change, it adds more noise, I'm not sure that ss2 or network-manager instead of wpa_supplicant is a better outcome, now you are just linearly increasing the cognitive demand of new sysadmins linearly with time. Sorry to be a bummer.
- pdimitar 9mo agoWhen attempting to install through go: go install github.com/karol-broda/snitch@latest I get this error message: go: github.com/karol-broda/snitch@latest: version constraints conflict: github.com/karol-broda/snitch@v0.1.8: parsing go.mod: module declares its path as: snitch but was required as: github.com/karol-broda/snitch
- Melonai 9mo agoThey declared their module with just their package name without a URL, it got fixed a few hours ago. I find it a bit interesting that Go even allows you to declare `module barename` in go.mod even though it loves breaking so many things if you do so. I sometimes try doing it for completely private projects but I always just declare some URL in the end, it's a weird anti-pattern in my opinion.
- PhilippGille 9mo agoThey fixed it 6 hours ago, but it's not in a release yet: https://github.com/karol-broda/snitch/commit/7fdb1ed477894f1fc6e02205456bba7fa7663728 https://github.com/karol-broda/snitch/commit/7fdb1ed477894f1...
- karol-broda 9mo agoi fixed it and created a release so building from @latest should work now
- hashstring 9mo agoName can be friendlier, tui looks nice!
- stavros 9mo agoThanks for this! I can never remember the netstat arguments, and it's a bit crazy that it doesn't come with sane defaults, so this is going to be really useful.
- karol-broda 9mo agoyea i was kinda fed up
- hwj 9mo agoThe README doesn't mention this, but on macOS it's also available via brew: `brew install snitch`
- karol-broda 9mo agodont think this is in homebrew/core, brew install snitch may be a different package, could you paste brew info snitch output? if its not this project, i will add a note to the readme to avoid confusion. but i will be creating a homebrew cask soon
- emaro 9mo agoI didn't verify anything, but used the brew install and the installed cli at least looks and behaves like I expected from this HN post.
- hwj 9mo ago$ brew info snitch ==> snitch: stable 0.1.8 (bottled), HEAD Prettier way to inspect network connections https://github.com/karol-broda/snitch Installed /opt/homebrew/Cellar/snitch/0.1.8 (9 files, 8.4MB) \* Poured from bottle using the formulae.brew.sh API on 2025-12-23 at 15:32:41 From: https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/s/snitch.rb License: MIT ==> Dependencies Build: go ==> Options --HEAD Install HEAD version
- rramadass 9mo agoAn old classic powerful network tool; Netwox (i.e. Network Toolbox with more than 200 tools) and Netwag (Tcl/Tk GUI) - https://ntwox.sourceforge.net/ https://ntwox.sourceforge.net/ and https://ntwag.sourceforge.net/ https://ntwag.sourceforge.net/ Howto Guide - https://anto.online/mastering-netwag-guide/ https://anto.online/mastering-netwag-guide/
- karol-broda 9mo agothis is supposed to be an actually maintained terminal utility for viewing ss/netstat data
- rramadass 9mo agoI was just pointing to another network tool used for all sorts of fine-grained networking jobs (eg. security testing and others) which might be helpful to others. It was created by Laurent Constantin (https://linuxsecurity.com/features/introduction-to-netwox-and-interview-with-creator-laurent-constantin https://linuxsecurity.com/features/introduction-to-netwox-an...) for his own needs and hence the TUI/GUI is not polished. But it is simple, direct and gets the job done which is what is important. And it is a mature tool (hence no need for active maintenance) available in all Linux distros.
- coolbean 9mo agoI wish there was a tool that also displayed current and accumulated transfer rate per socket/process. I use jnettop for this purpose, but I'm unhappy with its user interface.
- karol-broda 9mo agothat actually is planned for a future version
- INTPenis 9mo agoI've gotten used to ss now, and I quite like it, I just wish there was an option to not show the send/recv numbers. I never use them and the width is already so wide that the output barely fits into most terminals when you have them split vertically on a laptop screen. That said though, I'm not going to install snitch. The thing about ss is that it's already there, on every server I manage. And I definitely do not need a TUI for this. Snitch is something you might install in your homelab, or your workstations. But ss is still the default when you provision a lot of servers.
- karol-broda 9mo agofair point. ss stays the default on servers because it is already installed. snitch is for workstation/homelab debugging when i want quicker filtering and selection. also, i do not show send/recv yet, but if i add it later it will be optional (compact mode / toggle) so it fits in split panes.