network-monitoring

v2026.09.24

Real-time network traffic and per-process bandwidth monitoring. Use when finding which app consumes bandwidth, inspecting active connections, or capturing traffic samples.

GitHub
安装命令
npx skhub add laurigates/network-monitoring
Markdown
SKILL.md

Network Monitoring

When to Use This Skill

ScenarioUse this skillAlternative
Find which process is consuming bandwidthYes (bandwhich)
Monitor per-connection bandwidth in real timeYes (bandwhich)
Visually inspect traffic with protocol filteringYes (Sniffnet)
Capture a script-friendly sample of bandwidth dataYes (bandwhich -r)
Identify unexpected outbound connectionsYes (bandwhich)
Scan for open ports on a remote hostnetwork-discovery (RustScan, nmap)
Trace the route or diagnose packet lossnetwork-diagnostics (trippy)
Look up DNS records for a domaindns-tools (dog, dig)
Discover devices on the local L2 segmentlayer2-discovery (ARP/LLDP)
Load test an HTTP endpointhttp-load-testing (oha)
Inspect or configure the host's own IPs, links, or routesinterface-state (ip)

Expert knowledge for real-time network traffic monitoring using modern Rust-based tools: bandwhich for CLI-based per-process bandwidth analysis and Sniffnet for visual traffic inspection.

Core Expertise

Why These Tools

ToolTypeBest For
bandwhichCLIPer-process bandwidth, quick diagnostics, scripting
SniffnetGUIVisual analysis, long-term monitoring, filtering

Key Advantages

  • Per-process visibility: See which applications consume bandwidth (unlike traditional iftop)
  • Connection-level detail: Track individual connections to remote hosts
  • Modern Rust performance: Minimal overhead, safe memory handling
  • Cross-platform: Works on Linux, macOS, Windows

Privilege Requirements

Both tools require elevated privileges to capture network traffic:

# Run with sudo
sudo bandwhich

# Or grant capabilities (Linux, avoids sudo)
sudo setcap cap_net_raw,cap_net_admin+ep $(which bandwhich)

Essential Commands

bandwhich - CLI Bandwidth Monitor

Basic Usage

# Start monitoring (requires sudo or capabilities)
sudo bandwhich

# Monitor specific interface
sudo bandwhich -i en0
sudo bandwhich -i eth0

# Raw mode (no TUI, machine-readable)
sudo bandwhich -r

# Disable DNS resolution (faster startup)
sudo bandwhich -n

Output Modes

# Default TUI with three panels:
# - Processes (bandwidth by application)
# - Connections (bandwidth by socket)
# - Remote addresses (bandwidth by host)

# Raw output for scripting
sudo bandwhich -r
# Output: <interface>:<process>:<bytes_down>:<bytes_up>

# Combined options
sudo bandwhich -i en0 -n -r

TUI Navigation

KeyAction
TabSwitch between panels
Up/DownNavigate rows
qQuit

Sniffnet - GUI Traffic Monitor

Installation

# macOS
brew install sniffnet

# Cargo
cargo install sniffnet

# Or download from GitHub releases
# https://github.com/GyulyVGC/sniffnet/releases

Features

  • Real-time traffic charts
  • Filter by protocol, port, IP
  • Domain and provider identification
  • Geo-location of remote hosts
  • Export reports

Launch

# GUI application (requires sudo or admin)
sudo sniffnet

# On macOS, may need to grant network access in System Preferences

Common Patterns

Diagnose High Bandwidth Usage

# Quick check: which process is using bandwidth?
sudo bandwhich -n

# Watch specific interface during download
sudo bandwhich -i en0

Script-Friendly Monitoring

# Capture 10 seconds of raw data
sudo timeout 10 bandwhich -r > /tmp/bandwidth.log

# Parse raw output
cat /tmp/bandwidth.log | cut -d: -f2 | sort | uniq -c | sort -rn

Compare Interface Traffic

# Monitor WiFi
sudo bandwhich -i en0

# Monitor Ethernet (separate terminal)
sudo bandwhich -i en1

Identify Unexpected Connections

# Raw mode shows all connections
sudo bandwhich -r -n | grep -v "127.0.0.1" | head -20

Agentic Optimizations

ContextCommand
Quick bandwidth checksudo bandwhich -n (no DNS delay)
Machine-readable outputsudo bandwhich -r
Specific interfacesudo bandwhich -i <iface> -n
Capture samplesudo timeout 5 bandwhich -r > /tmp/bw.log
Parse top processessudo bandwhich -r | cut -d: -f2 | sort | uniq -c

Quick Reference

bandwhich Flags

FlagLongDescription
-i--interfaceMonitor specific network interface
-r--rawMachine-readable output (no TUI)
-n--no-resolveSkip DNS resolution (faster)
-h--helpShow help
-V--versionShow version

Raw Output Format

<interface>:<process_name>:<bytes_downloaded>:<bytes_uploaded>

Example:

en0:firefox:1048576:65536
en0:curl:4096:1024

Installation

bandwhich

# macOS
brew install bandwhich

# Cargo
cargo install bandwhich

# Linux (grant capabilities to avoid sudo)
sudo setcap cap_net_raw,cap_net_admin+ep $(which bandwhich)

Sniffnet

# macOS
brew install sniffnet

# Cargo
cargo install sniffnet

# GitHub releases (pre-built binaries)
# https://github.com/GyulyVGC/sniffnet/releases

Troubleshooting

Permission Denied

# Use sudo
sudo bandwhich

# Or set capabilities (Linux)
sudo setcap cap_net_raw,cap_net_admin+ep $(which bandwhich)

# Verify capabilities
getcap $(which bandwhich)

Interface Not Found

# List available interfaces
ip link show        # Linux
networksetup -listallhardwareports  # macOS
ifconfig -l         # BSD/macOS

# Then specify
sudo bandwhich -i <interface_name>

DNS Resolution Slow

# Disable DNS lookup
sudo bandwhich -n

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

networking-plugin/skills/network-monitoring

默认分支

main

最新提交

1668324

Tree SHA

b2d4cc3