Babyshark – Wireshark made easy (terminal UI for PCAPs)
Domains-first TUI cuts through Wireshark noise; live capture works but ecosystem dominated by tcpdump+Wireshark.
Real-time network diagnostics in your terminal. One command, zero config, instant visibility.
Wireshark-in-terminal with TCP reassembly, GeoIP, and htop-style UX. 20-year pro's tool.
Network engineers, systems administrators, platform engineers debugging live traffic.
Wireshark · htop · nethogs
Live interface bandwidth with sparkline history Active connections with process/PID mapping Deep packet capture with protocol decoding (DNS, TLS/SNI, HTTP, ICMP, ARP, DHCP, NTP) Wireshark-style display filters (tcp and port 443, contains "google", dns or icmp) TCP stream reassembly with text/hex views TCP handshake timing (SYN→SYN-ACK→ACK latency) GeoIP and RDAP whois lookups PCAP export Protocol hierarchy statistics
Built with Rust, ratatui, and libpcap. Cross-platform: macOS, Linux, and Windows.
cargo install netwatch-tui
I've been in network/trading systems engineering for 20 years and wanted a tool that sits between netstat and Wireshark — something you can fire up in a second to answer "what's happening on my network right now?" without the overhead of a full GUI.
Feedback welcome — especially on the packet decoding and filter syntax.
Domains-first TUI cuts through Wireshark noise; live capture works but ecosystem dominated by tcpdump+Wireshark.
ncdu replacement with 2x speed and trash support, but ncdu already solved the problem well.
Reverse-engineered USB protocol in 24hrs; $30 BLE sniffer now works on Linux.
Turns 5G NR packet captures into readable sequence diagrams with AI-root-cause analysis.
House MD fan tribute with character selection, but don't actually diagnose yourself here.
Finally sees real client traffic unlike MCP Inspector—single binary, zero config required.