domcyrus/rustnet
81.0
Strong · 30 September 2026
71.6k
lines of production code
Rust
primary language
2
measurements over time
What this system is
RustNet is a cross-platform network monitoring tool that performs deep packet inspection and connection tracking across Linux, macOS, Windows, and FreeBSD. It provides per-connection process attribution and container identification using platform-specific APIs, while enforcing security through post-initialization privilege dropping and sandboxing. The system offers both an interactive terminal interface and a headless mode for machine-readable JSON output, supporting PCAP export and integration with external observability pipelines.
How it got here
2025 — Initial release and packaging
10 changes.
This period covers the initial release of RustNet v1.6.0, establishing the core cross-platform network monitoring capabilities including deep packet inspection, TUI, and headless modes. The work focused on structuring the codebase into a modular Cargo workspace and implementing comprehensive packaging for Linux (RPM, Debian/PPA), macOS, and Windows to enable broad distribution.
2026 — Modular architecture and security hardening
10 changes.
The project restructured its codebase into a modular architecture, separating core network analysis, host attribution, and capture logic into distinct crates while introducing a tabbed UI. Significant effort was dedicated to security hardening through a new sandboxing crate and performance improvements via optimized capture wait logic and benchmarking. Additionally, the work expanded cross-platform support and added headless monitoring capabilities with machine-readable JSON output.
Features
Add container and Kubernetes attribution for network connections
The network module now enriches connection data with container and Kubernetes metadata. On Linux, it identifies Docker, Podman, and LXC containers by parsing cgroup paths and loading runtime metadata from local disk files, and it resolves Kubernetes pod and container identities from cgroup layouts (supporting both cgroup v1 and v2). A Kubernetes resolver with Auto/On/Off modes detects if the app runs inside a pod and caches results per PID. This attribution is performed without requiring access to a runtime daemon or elevated privileges beyond what is needed for packet capture.
src/network · high confidence
Added IANA services port database
The \crates/rustnet-core/assets/services\ file has been added to the project, containing the standard IANA network services and port assignments (based on the 2021-01-19 update). This asset provides the reference data for mapping well-known TCP, UDP, and SCTP port numbers to their corresponding service names, enabling the application to identify network services by port.
crates/rustnet-core/assets · high confidence
Initial RPM packaging specification for RustNet
The RPM package specification (rustnet.spec) has been added, enabling the distribution of RustNet version 1.6.0 via RPM-based Linux distributions. This packaging includes build requirements for Rust, libpcap, and eBPF tooling, and configures the binary to run with minimal Linux capabilities (cap\_net\_raw, cap\_bpf, cap\_perfmon) for secure packet capture and process tracking. The package also installs desktop integration files, icons, and documentation, with specific build and runtime dependencies adjusted for openSUSE compatibility.
rpm · high confidence
Initial Ubuntu PPA packaging support for RustNet
RustNet is now available as a native package for Ubuntu 22.04, 24.04, and 26.04 via the \domcyrus/rustnet\ PPA. Users can install the tool using \sudo add-apt-repository ppa:domcyrus/rustnet\ and \sudo apt install rustnet\. The package includes a desktop entry, icons, shell completions, and manpages. It is built with Rust 1.88 and includes eBPF support for enhanced process detection, with capabilities automatically configured during installation to allow packet capture without requiring full root privileges.
debian · high confidence
Initial cross-platform packaging resources and Windows UTF-8 fix
This change introduces the foundational packaging assets for Linux, macOS, and Windows, including a desktop entry for Linux, an application bundle with a terminal wrapper for macOS, and a WiX installer definition for Windows. It also adds a Windows application manifest that sets the active code page to UTF-8 to prevent character encoding errors with network device descriptions, and provides documentation for generating and managing icon artwork across platforms.
resources · high confidence
Initial release of RustNet network monitor with TUI, headless, and export features
This change introduces the RustNet application, a cross-platform network monitoring tool. It provides an interactive terminal user interface (TUI) built on Ratatui, featuring live connection tracking, deep packet inspection (DPI), process attribution, and configurable color themes. For automated or remote usage, it supports a headless mode that outputs JSON snapshots or streams JSONL data, with optional filtering. The tool also includes packet capture capabilities, allowing exports to standard PCAP and annotated PCAPNG formats for analysis in tools like Wireshark. Additional features include GeoIP location lookups, reverse DNS resolution, and configurable refresh intervals.
src · high confidence
Initial release of RustNet v1.6.0
RustNet is a cross-platform network monitoring tool featuring deep packet inspection (DPI) for protocols such as HTTP, HTTPS, DNS, SSH, FTP, QUIC, and more. It provides a terminal user interface (TUI) and a headless mode for production monitoring, with per-connection process attribution on Linux (eBPF/procfs), macOS (PKTAP/lsof), Windows (ETW/IP Helper), and FreeBSD (sockstat). The application supports PCAP/PCAPNG export, JSON logging, and runs with minimal privileges via platform-specific sandboxing (Landlock, Seatbelt, restricted tokens). Installation is available via Homebrew, Chocolatey, Scoop, PPA, COPR, and Docker.
(repo-wide) · high confidence
Introduce rustnet-host crate for cross-platform process attribution and socket inventory
The new \rustnet-host\ crate provides a unified interface for per-connection process attribution and a point-in-time host socket inventory across Linux, macOS, Windows, and FreeBSD. It exposes a \ProcessLookup\ trait that identifies the owning process (PID, name, UID/GID, executable, and lineage) using the best available OS mechanism—eBPF with procfs fallback on Linux, PKTAP/libproc on macOS, ETW on Windows, and \sockstat\/sysctl on FreeBSD. Additionally, it offers a \socket\_snapshot\ API that lists all active host sockets (including TCP listeners and UDP endpoints) with their native states, independent of captured traffic.
crates/rustnet-host · high confidence
New headless capture example and Kubernetes resolver smoke test
Added two new examples to demonstrate core capabilities without the TUI. The \headless\ example (\examples/headless.rs\) provides a low-level, machine-readable connection summary by chaining \rustnet-capture\, \rustnet-core\, and \rustnet-host\, including sandboxing and process attribution. The \k8s\_resolver\_check\ example (\examples/k8s\_resolver\_check.rs\) serves as a smoke test for Kubernetes pod and container attribution, enriching a given PID with cgroup-based metadata when built with the \kubernetes\ feature.
examples · high confidence
New headless mode for machine-readable monitoring output
A new headless output module has been added to provide stable, versioned JSON and JSON Lines snapshots of application state for non-interactive, automated monitoring. This feature introduces a dedicated schema (version 1) that projects internal state into a wire format independent of implementation details, supporting both live streaming (JSONL) and terminal-only (JSON) modes. It includes an asynchronous writer to prevent blocked I/O from delaying shutdown, handles broken pipes gracefully as clean exits, and allows filtering connections via query strings, enabling reliable integration with external observability pipelines.
src/headless · high confidence
New modular UI architecture with tabbed layout and shared components
The terminal UI has been restructured into a modular, tabbed interface (Overview, Details, Activity, Graph, Host) using a Component pattern. This introduces a unified connection table with responsive column visibility, a clipboard system with sandbox awareness, and shared input handling for navigation and scrolling across all tabs.
src/ui · high confidence
New reusable network-analysis core library
The \rustnet-core\ crate introduces a platform-independent, reusable library for network analysis, separating packet parsing, protocol types, deep packet inspection (DPI), link-layer parsers, connection merging, and DNS/GeoIP/OUI lookups from the platform-specific capture logic. This core provides capabilities for parsing Ethernet, Linux SLL/SLL2, PKTAP, raw IP, and TUN/TAP link layers, along with IPv4/IPv6, TCP, UDP, ICMP, and IGMP. It includes DPI for HTTP, HTTPS/TLS (with SNI extraction), DNS, SSH, QUIC, NTP, mDNS, LLMNR, DHCP, SNMP, SSDP, NetBIOS, and BitTorrent. The library also features connection merging with protocol-aware lifecycle tracking, reusable filtering and retention policies, GeoIP lookups, reverse DNS with background async resolution and caching, and OUI vendor resolution.
crates/rustnet-core/src · high confidence
New rustnet-sandbox crate for post-initialization security hardening
A new \rustnet-sandbox\ crate has been introduced to enforce a post-initialization security model across the RustNet workspace. This crate provides a unified \apply\_sandbox\ entry point that restricts process capabilities and identity after privileged initialization (such as opening capture handles and loading eBPF programs) is complete. On Linux, it drops capabilities like \CAP\_NET\_RAW\ and \CAP\_BPF\, sets \PR\_SET\_NO\_NEW\_PRIVS\, and applies Landlock restrictions for filesystem and network access. On macOS, it utilizes the Seatbelt profile to block outbound network traffic and restrict filesystem writes to user home directories. Windows receives privilege removal and job object restrictions to block child process creation, while FreeBSD currently implements root UID dropping. The crate also includes a \privdrop\ module to irreversibly transition the process from root to an unprivileged user (e.g., \SUDO\_UID\ or \nobody\) and ensures that existing file descriptors remain valid across this transition.
crates/rustnet-sandbox · high confidence
New utility scripts for maintenance, packaging, and release validation
This update adds several new shell and Python scripts to the project to support daily operations and release workflows. The \clear\_old\_logs.sh\ script allows users to automatically remove old log files while preserving the most recent one. The \pre-release-check.sh\ script provides a validation suite for release candidates, verifying version consistency across Cargo.toml and RPM specs, checking changelog entries, running clippy and tests, and ensuring Dockerfile assets are present. The \test-deb-build.sh\ script enables local testing of Debian package builds using Docker. Additionally, \generate-icons.py\ automates the creation of platform-specific icon assets (ICO, ICNS, PNG) from the main SVG, \pcap\_enrich.py\ enriches PCAP captures with process and GeoIP sidecar data, \debug-attribution.sh\ aids in diagnosing short-lived process attribution issues, and \record-rustnet-demo.sh\ automates the generation of demo GIFs and screenshots using VHS.
scripts · high confidence
Architecture
Introduce platform abstraction for process attribution and degradation reporting
The \src/network/platform\ module now serves as the central re-export shim for the \rustnet-host\ process-attribution API, exposing \create\_process\_lookup\ and \DegradationReason\ to the rest of the application. This change centralizes how the binary accesses process identification logic while explicitly separating concerns: interface statistics remain in \rustnet-core\ and sandboxing/root-privilege dropping remains in \rustnet\_sandbox\. Additionally, macOS-specific degradation reporting (\report\_pktap\_degradation\) is exposed to allow the host crate to signal when PKTAP is unavailable without forcing a dependency on \rustnet-capture\.
src/network/platform · high confidence
Project restructured into a Cargo workspace with dedicated crates
The project has been refactored from a single crate into a Cargo workspace containing four distinct crates: \rustnet-core\ (network analysis, packet parsing, and DPI), \rustnet-capture\ (packet capture backend), \rustnet-host\ (process attribution and socket inventory), and \rustnet-sandbox\ (privilege dropping and sandboxing). This separation allows for better modularity, with dependencies like \libbpf-rs\ and \procfs\ now isolated in the host crate and core logic moved to the core crate, while the main binary \rustnet-monitor\ acts as the integration point.
(dependencies) · high confidence
Restructured application core into modular subsystems
The application's internal architecture has been reorganized from a single monolithic module into a set of specialized, cohesive modules. This change introduces dedicated modules for packet capture and processing (capture.rs), process and container attribution (enrichment.rs), structured event logging (logging.rs), secure output file handling (output.rs), packet queue backpressure (packet\_queue.rs), PCAPNG export (pcapng\_export.rs), worker lifecycle management (runtime.rs), and periodic sampling (sampling.rs). This modularization improves code maintainability and separation of concerns within the application's core logic.
src/app · high confidence
Behavioural changes
Refactored capture wait logic to prevent busy-spinning and improve cross-platform readiness
The \rustnet-capture\ crate now uses a dedicated, bounded-wait policy for packet reading that eliminates busy-spinning when no packets are available. On Unix systems, it leverages the libpcap selectable file descriptor via \poll\, while on Windows it waits on the Npcap capture event. A shared 10 ms idle budget ensures the application can check for shutdown signals and flush partial batches without blocking indefinitely or consuming CPU cycles. This change also includes tests to verify that the wait mechanism correctly handles spurious readiness, timeouts, and unsupported backends without retrying or spinning.
crates/rustnet-capture · high confidence
Test coverage
Add benchmark suite for network performance; Added integration tests for platform lookups, Kubernetes resolution, and CLI startup validation.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 78 → 81 (+3.1)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 83 → 83 (+0.2)
- Architecture 99 → 92 (-6.7)
- Maturity 76 → 80 (+4.0)
- Readiness 85 → 83 (-2.7)
- Security 73 → 80 (+6.7)
- Performance 85 (new)
Resolved (28)
- Change coupling: mod.rs ↔ filter.rs (crates/rustnet-core/src/network/dpi/mod.rs)
- ConnectionFilter::matches (cyclomatic 21) (src/filter.rs)
- Duplicated block (8 lines × 3) (src/ui/tabs/activity.rs)
- Duplicated block (9 lines × 2) (src/ui/tabs/activity.rs)
- FileTooLong: src/main.rs (src/main.rs)
- FunctionTooLong: rustnet_monitor::main (src/main.rs)
- FunctionTooLong: rustnet_monitor::run_ui_loop (src/main.rs)
- FunctionTooLong: rustnet_monitor::ui::tabs::overview::draw_interface_stats_with_graph (src/ui/tabs/overview.rs)
- High: security finding (details withheld)
- Hotspot: crates/rustnet-core/src/network/dpi/bittorrent.rs (crates/rustnet-core/src/network/dpi/bittorrent.rs)
- Hotspot: crates/rustnet-core/src/network/dpi/quic/packet.rs (crates/rustnet-core/src/network/dpi/quic/packet.rs)
- Hotspot: crates/rustnet-core/src/network/dpi/quic/tls.rs (crates/rustnet-core/src/network/dpi/quic/tls.rs)
- Hotspot: crates/rustnet-core/src/network/dpi/tls_common.rs (crates/rustnet-core/src/network/dpi/tls_common.rs)
- Hotspot: crates/rustnet-core/src/network/types/identity.rs (crates/rustnet-core/src/network/types/identity.rs)
- Hotspot: crates/rustnet-host/src/lib.rs (crates/rustnet-host/src/lib.rs)
- Hotspot: src/app/pcapng_export.rs (src/app/pcapng_export.rs)
- Hotspot: src/filter.rs (src/filter.rs)
- Hotspot: src/main.rs (src/main.rs)
- Hotspot: src/ui/state.rs (src/ui/state.rs)
- Hotspot: src/ui/theme/definitions.rs (src/ui/theme/definitions.rs)
- …and 8 more
New (49)
- ActivityTab::handle_key (cognitive 26) (src/ui/tabs/activity.rs)
- ActivityTab::handle_key (cyclomatic 24) (src/ui/tabs/activity.rs)
- ClassTooLong: App (src/app/state.rs)
- ConnectionFilter::matches (cyclomatic 25) (crates/rustnet-core/src/network/filter.rs)
- DnsAnalyticsTracker::snapshot (cognitive 28) (crates/rustnet-core/src/network/dns_analytics.rs)
- DnsAnalyticsTracker::snapshot (cyclomatic 17) (crates/rustnet-core/src/network/dns_analytics.rs)
- DnsResolver::start_with_spawner (cognitive 36) (crates/rustnet-core/src/network/dns.rs)
- DnsResolver::start_with_spawner (cyclomatic 20) (crates/rustnet-core/src/network/dns.rs)
- DnsResolver::stop (cognitive 18) (crates/rustnet-core/src/network/dns.rs)
- FileTooLong: app/capture.rs (src/app/capture.rs)
- FileTooLong: app/state.rs (src/app/state.rs)
- FileTooLong: network/process_activity.rs (crates/rustnet-core/src/network/process_activity.rs)
- FunctionTooLong: rustnet_monitor::bootstrap::run (src/bootstrap.rs)
- FunctionTooLong: rustnet_monitor::tui::run (src/tui.rs)
- FunctionTooLong: rustnet_monitor::ui::tabs::activity::draw_process_details (src/ui/tabs/activity.rs)
- High: security finding (details withheld)
- Hotspot: crates/rustnet-core/src/network/filter.rs (crates/rustnet-core/src/network/filter.rs)
- Hotspot: src/tui.rs (src/tui.rs)
- Hotspot: src/ui/mod.rs (src/ui/mod.rs)
- Inconsistent builder pattern naming. with_defaults and with_defaults_deferred suggest a builder pattern, but try_with_defaults returns a Result and likely constructs the resolver directly. This mixes builder-style fluent methods with constructor-style methods. with_defaults_deferred is also a confusing name; it's unclear what 'deferred' means in this context (lazy initialization? async?).
- …and 29 more
Changes since last survey
- 31 commits — 27 feature/other, 4 fixes
By area
- (root) — 18 commits
- src/ui — 6 commits
- .github/workflows — 2 commits
- crates/rustnet-host — 2 commits
- crates/rustnet-core — 1 commit
- resources/packaging — 1 commit
- src/app — 1 commit
Notable commits
- fix: fix(ebpf): align ConnInfo ABI on 32-bit targets (#612)
- fix: fix: navigate connections with the Details mouse wheel (#621)
- fix: fix: retain short Kubernetes flow attribution (#634)
- fix: fix: show DNS attribution in application displays (#638)
- change: Improve compact layouts and application activity (#617)
- change: Refresh terminal signal artwork (#626)
- change: chore(deps): bump clap_complete in the rust-dependencies group (#619)
- change: chore(deps): bump debian from d7e1218 to a99cfc5 in the docker group (#644)
- change: chore(deps): bump maxminddb in the rust-dependencies group (#613)
- change: chore(deps): bump rust from bce1476 to 3999a7f in the docker group (#614)
- change: chore(deps): bump the actions group with 2 updates (#615)
- change: chore(deps): bump the rust-dependencies group with 2 updates (#616)
- change: chore(deps): bump the rust-dependencies group with 3 updates (#610)
- change: ci: keep FreeBSD VM builds in rustnet-bsd (#623)
- change: design(ui): unify traffic colors and refresh Activity layout (#607)
- change: docs: add platform badges to READMEs (#625)
- change: docs: align guides with current behavior (#633)
- change: docs: clarify packet capture privileges (#632)
- change: docs: clarify unreleased features and release links (#622)
- change: docs: document Scoop installation (#628)
- …and 11 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
domcyrus/rustnet was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 16ad7697526bcb9ffef3e61f5e174065aa4b6a31 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.