π§ NetHtop++ (alpha)
Network Hunt Console with Ghost Response Playbooks
The NETWORK ARMY KNIFE you wish you had 10 years ago.
Those screenshots are from an APT infected macOS system. Since it is a Mac mini there are a lot of interfaces but NetHtop++ only lists the interface running on your system. Not all possible interfaces. 60 ghost sockets is not normal macOS behaviour, nor any normal system
π§° What is NetHtop++?
NetHtop++ is a real-time network inspection and response console built for operators, analysts, hackers, blue teamers, red teamers, and those who need to know what the hell is going on β fast.
Inspired by htop, but for sockets and flows, NetHtop++ fuses multiple tools into a single, powerful, terminal-native battlefield command interface. Run with sudo since... Well it is interactive and can do many things that require priviledges. IE: killing sockets, adding pf rules, killswitch feature from the ghost sockets interface but be careful using the playbook in the ghost sockets overlay because it combines powerful features that could break your networking. Always backup you pf.conf before adding the whole ghost sockets list to pf. I'll add other firewalls support soon or tweak the script to include the firewall you use.
π§ It's htop for networks.
π» It's a ghost hunter.
π£ It's a one-key SIEM.
βοΈ It's the Swiss Army Knife of NetOps.
𧨠Features
| Feature | Description |
|---|---|
| π Live Socket Inspector | Real-time view of all TCP/UDP connections, resolved hostnames, states, PIDs, and more. |
| π Ghost Socket Detection | Reveal and count stealthy sockets not exposed via typical tools, scored by confidence. |
| π― One-Key Tracing | Press z to trace route of selected connection. |
| π‘ Targeted Tcpdump | Press t to launch a targeted tcpdump on the selected connection's interface. |
| π§Ύ PCAP Logging | Captures are auto-saved in nethtop directory. |
| π Interface Throughput Graphs | TX/RX bars per interface. Always visible. Real-time updates. |
| πͺ Process Killing | Kill offending connections instantly with p. |
| π§ Playbooks + Countermeasures | Ghost socket recon tools and embedded response flow. |
| π Resolve Mode | Instantly resolve IPs to hostnames (r). |
| πΎ Export to Log | Full session dump to log file. |
| π₯οΈ Terminal-aware Layout | ASCII banner enforces optimal terminal width and mental clarity. |
π§ Philosophy
βThis is not a tool you run. This is a console you deploy.β
From the moment you launch, NetHtop++ sets the stage:
- ASCII banner primes your operator mindset.
- Terminal resizes itself to fit tactical layout.
- Keys behave like live toggles. No menus. No clutter.
You're not watching the network.
You're interrogating it.
Stop duct-taping five tools together. Hereβs your damn console.
π§ Requirements
- Python 3.8+
psutil>=5.9ipwhois>=1.2(optional, for IP enrichment)
Platform-specific notes
| Platform | Extra dependency | Notes |
|---|---|---|
| macOS π | None | Full features: tcpdump capture, pfctl firewall blocks, launchd scanning |
| Linux π§ | None | Full features: tcpdump capture, /proc socket control |
| Windows πͺ | windows-curses>=2.3 |
tcpdump/pfctl/launchd gracefully disabled; use Kill Process for socket control |
Same file, all platforms β
nethtop++.pyauto-detects your OS and adapts.
π‘οΈ Read-only by default
NetHtop++ opens in read-only mode: p (kill), x (close socket), and the
ghost playbook (K graceful kill, F firewall block, R restart daemons,
H hard kill) all require a y/N confirmation before acting. The header
shows [READ-ONLY] while this is active.
sudo python3 nethtop++.py --response # response mode: destructive keys act immediatelyResponse mode displays [RESPONSE] in the header. Use it deliberately β it
skips every confirmation.
Privilege separation
- Run the console unprivileged for monitoring. It works fine without root.
- Privileged operations (
pfctlblocks, killing other users' processes,/procsocket access) only succeed when you run elevated β usesudo python3 nethtop++.py(optionally with--response) only for actual response work. - Ghost detection accounts for the privilege gap: an unprivileged
lsofcannot attribute other users' sockets, so those inventory differences are reported at lower confidence with a note, and the alert carries a hint to re-scan elevated for full-strength attribution.
Ghost sockets are a confidence score, not a binary verdict
Kernel (netstat -anv on macOS, /proc/net/{tcp,tcp6,udp,udp6} on Linux)
and userland (lsof) inventories are compared on canonical host:port keys.
Each mismatch is scored 0.0β1.0 with its reasons:
| Signal | Effect |
|---|---|
| Owned by a live process (psutil) | β0.40 β likely a tool race |
| Unprivileged scan | β0.35 β may be another user's socket |
Unowned LISTEN socket |
+0.15 |
Active ESTABLISHED session |
+0.05 |
| Persistent across scans | +0.10 per scan (max +0.30) |
Entries at/above 0.70 raise a warning; the overlay sorts by confidence.
When lsof or netstat is missing (or lsof returns nothing), detection
reports "ghost detection unavailable" β it never treats an empty
inventory as "no ghosts".
Optional tools
Detected at startup and reported in the status line:
| Tool | Feature |
|---|---|
lsof |
Ghost detection (userland inventory) |
netstat |
Ghost detection (kernel inventory, macOS/BSD) |
tcpdump |
Packet capture |
traceroute / tracepath |
Route tracing |
Missing tools disable their feature gracefully β no crashes, no fake data.
Tests
Parser fixtures + unit tests live in tests/ (stdlib unittest, zero extra
dependencies) and cover macOS netstat -anv, Linux /proc/net, and lsof -F
output:
python3 -m unittest discover -s tests -v
π Installation
macOS / Linux
git clone https://github.com/m10ust/nethtop.git cd nethtop pip install -r requirements.txt python3 nethtop++.py # read-only monitoring - no sudo needed sudo python3 nethtop++.py --response # elevate only for response work
Windows
git clone https://github.com/m10ust/nethtop.git cd nethtop pip install -r requirements.txt python nethtop++.py
Windows doesnβt need
sudoβ just run it. Packet capture (tcpdump) and firewall blocks (pfctl) show a helpful message instead of crashing.