v0.2.1 Beta macOS, Windows, Linux MIT License
Every packet, accounted for.
Pruftnet is an open-source packet analyzer. Capture on several interfaces at once, decode any field down to its bytes, and see where every packet went: written to disk, dissected, or counted as dropped.
Capture
Every interface, one capture.
Select any number of interfaces and start a single capture. Each interface reads into its own bounded queue, so a busy link never starves a quiet one.
- Filter
- BPF expressions, compiled by libpcap before packets reach the app
- Per interface
- Promiscuous or monitor mode, link type, timestamp source
- Buffers
- Snapshot length, kernel buffer and ring size, all bounded
- Engine
- Native C++ worker on libpcap (macOS, Linux) or Npcap (Windows)
Capture settings
Configure packet acquisition before starting. Active capture settings are read-only.
Capture filter
Applied by libpcap before packets enter the application.
Interfaces
Link and timestamp options are resolved from each interface's capabilities.
en0 Capture interface
ap1 Capture interface
Buffers
Memory is bounded again by the backend and native worker.
Inspection
Point at a field. See its bytes.
Pruftnet decodes 38 protocols, from Ethernet and VLAN tags to DNS, TLS and QUIC, and reassembles TCP streams before reading the application layer.
Accounting
Know where every packet went.
Each capture keeps a ledger from the network card to the decoded tree. When the numbers do not add up, you see which stage dropped what.
Capture statistics
Throughput, queue pressure, persistence and analysis from one live ledger.
Capture writer is keeping up
Commit throughput
38,010/s
Capture queue pressure
0.0%Capture source
- Observed
- 6,707,257
- Kernel loss
- 0
- Interface loss
- 0
- Dispatch errors
- 0
- Invalid payload
- 0
Capture queue
- Accepted
- 6,707,257
- Queue full
- 0
- Oversize
- 0
- Current
- 0 pkt · 0 B
Persistence
- Persisted
- 6,707,257
- Disk retained
- 2.6 GiB
- Write failures
- 0
- Unpersisted
- 0 pkt
- Retention evicted
- 0 pkt
Analysis
- Analyzed
- 6,707,257
- Backlog
- 0 pkt · 0 B
- Analysis gaps
- 0
- Errors
- 0
Packet conservation
liveen0
capturing-
Disk before analysis
Packets are committed to a pcapng spool first. A slow dissector delays the view, never the capture.
-
Recovers from crashes
After a crash, the capture reopens with every packet up to the last complete one. A torn tail is cut, not guessed.
-
Loss has a name
Kernel drops, interface drops, a full queue, write failures and retention are counted separately and reconciled live.
Performance
Numbers from a laptop, not a lab.
The capture path is native C++ from libpcap to disk, and the dissectors parse without allocating once warm. These are Release builds on an ordinary developer machine.
- Dissected on a single core
- 1.3 M packets/s
- packet_parser_benchmark: Ethernet / IPv4 / UDP frames, 31 fields each.
- Captured, written to pcapng and dissected
- 180 k packets/s
- End-to-end replay of 982,100 packets of mixed DNS, TLS, QUIC and HTTP traffic.
- Durable pcapng writes
- 600 MB/s
- sniffing_runtime_benchmark: 1,514 byte frames committed to the capture spool.
Overload, on purpose
In the end-to-end run the replay offered packets faster than the capture queue could take them. Pruftnet kept what it could and counted the rest, to the packet.
| offered | 982,100 |
| written and dissected | 290,178 |
| dropped, queue full | 691,922 |
| unaccounted | 0 |
Measured on Apple M1 Pro, 16 GB, macOS 27, Release build, October 2026. Benchmarks live in packages/core/cpp/benchmarks .
Keyboard
Every action is a command.
Press ⌘ K and type. The command palette, the menu bar and the shortcuts share one list, so nothing is reachable only by mouse.
- Command Palette ⌘K
- New Capture ⌘N
- Start or stop capture ⌘E
- Export Capture ⌘⇧E
- Capture Workspace ⌘1
- History ⌘2
- Settings ⌘,
- Back ⌥←
- Toggle Sidebar ⌘B
Ctrl and Alt replace ⌘ and ⌥ on Windows and Linux.
Runs where you work
One app, two ways to open it.
Captures export to pcapng or classic pcap, so they open in Wireshark, tcpdump or whatever comes next in your pipeline.
Desktop app
A native window on macOS, Windows and Linux, with the menu bar, shortcuts and file dialogs you expect.
Local server
The same interface in your browser. Run ./pruftnet serve and open http://127.0.0.1:3000. It listens on localhost only.
Install
Running in a few minutes.
macOS
macOS 15 or later, Apple Silicon or Intel.
- Builds are not notarized yet. If macOS blocks the first launch, choose Open Anyway in System Settings › Privacy & Security.
- Live capture needs access to /dev/bpf*. Wireshark’s ChmodBPF provides it, or grant it for the session:
sudo chown "$USER" /dev/bpf* Windows
Windows on x64.
- Install Npcap first. Pruftnet uses it for capture and does not bundle it.
- The installer is not signed yet, so Windows may show a publisher warning.
Linux
Ubuntu 24.04+ or Debian 13+, x64 or ARM64.
- Use the Debian package for live capture; AppImage cannot keep file capabilities.
- Grant capture rights to the native worker only, never to the app itself:
sudo setcap cap_net_raw,cap_net_admin=eip /opt/Pruftnet/resources/native/pruftnet_capture_worker