v0.2.1 Beta macOS, Windows, Linux MIT License

Every packet, accounted for.

Pruftnet is an open-source packet analyzer. Capture on several interfaces at once, decode any field down to its bytes, and see where every packet went: written to disk, dissected, or counted as dropped.

Pruftnet capture workspace: a packet list, the decoded fields of a TLS ClientHello with the server name selected, its bytes highlighted in the hex view, and live capture statistics.

Capture

Every interface, one capture.

Select any number of interfaces and start a single capture. Each interface reads into its own bounded queue, so a busy link never starves a quiet one.

Filter
BPF expressions, compiled by libpcap before packets reach the app
Per interface
Promiscuous or monitor mode, link type, timestamp source
Buffers
Snapshot length, kernel buffer and ring size, all bounded
Engine
Native C++ worker on libpcap (macOS, Linux) or Npcap (Windows)

Capture settings

Configure packet acquisition before starting. Active capture settings are read-only.

Capture filter

Applied by libpcap before packets enter the application.

Interfaces

Link and timestamp options are resolved from each interface's capabilities.

en0

Capture interface

ap1

Capture interface

Buffers

Memory is bounded again by the backend and native worker.

Inspection

Point at a field. See its bytes.

Pruftnet decodes 38 protocols, from Ethernet and VLAN tags to DNS, TLS and QUIC, and reassembles TCP streams before reading the application layer.

Frame 8679 · TLS ClientHello 157 bytes

Accounting

Know where every packet went.

Each capture keeps a ledger from the network card to the decoded tree. When the numbers do not add up, you see which stage dropped what.

Capture statistics

Throughput, queue pressure, persistence and analysis from one live ledger.

Capture writer is keeping up

Commit throughput

38,010/s

Observed Persisted Analyzed
0 20K 40K 60K
15:32:04 15:33:04
1 min visible Rolling window · 120/120 samples · oldest samples are replaced

Capture queue pressure

0.0%

Capture source

Observed
6,707,257
Kernel loss
0
Interface loss
0
Dispatch errors
0
Invalid payload
0

Capture queue

Accepted
6,707,257
Queue full
0
Oversize
0
Current
0 pkt · 0 B

Persistence

Persisted
6,707,257
Disk retained
2.6 GiB
Write failures
0
Unpersisted
0 pkt
Retention evicted
0 pkt

Analysis

Analyzed
6,707,257
Backlog
0 pkt · 0 B
Analysis gaps
0
Errors
0

Packet conservation

live
Observed 6,707,257 = 6,707,257
Queue 6,707,257 = 6,707,257
Analysis 6,707,257 = 6,707,257

en0

capturing
Queue 0/1,024
Bytes 0 B
Peak 214
Lost 0
  1. Disk before analysis

    Packets are committed to a pcapng spool first. A slow dissector delays the view, never the capture.

  2. Recovers from crashes

    After a crash, the capture reopens with every packet up to the last complete one. A torn tail is cut, not guessed.

  3. Loss has a name

    Kernel drops, interface drops, a full queue, write failures and retention are counted separately and reconciled live.

Performance

Numbers from a laptop, not a lab.

The capture path is native C++ from libpcap to disk, and the dissectors parse without allocating once warm. These are Release builds on an ordinary developer machine.

Dissected on a single core
1.3 M packets/s
packet_parser_benchmark: Ethernet / IPv4 / UDP frames, 31 fields each.
Captured, written to pcapng and dissected
180 k packets/s
End-to-end replay of 982,100 packets of mixed DNS, TLS, QUIC and HTTP traffic.
Durable pcapng writes
600 MB/s
sniffing_runtime_benchmark: 1,514 byte frames committed to the capture spool.

Overload, on purpose

In the end-to-end run the replay offered packets faster than the capture queue could take them. Pruftnet kept what it could and counted the rest, to the packet.

offered 982,100
written and dissected 290,178
dropped, queue full 691,922
unaccounted 0

Measured on Apple M1 Pro, 16 GB, macOS 27, Release build, October 2026. Benchmarks live in packages/core/cpp/benchmarks .

Keyboard

Every action is a command.

Press ⌘ K and type. The command palette, the menu bar and the shortcuts share one list, so nothing is reachable only by mouse.

  • Command Palette ⌘K
  • New Capture ⌘N
  • Start or stop capture ⌘E
  • Export Capture ⌘⇧E
  • Capture Workspace ⌘1
  • History ⌘2
  • Settings ⌘,
  • Back ⌥←
  • Toggle Sidebar ⌘B

Ctrl and Alt replace ⌘ and ⌥ on Windows and Linux.

Runs where you work

One app, two ways to open it.

Captures export to pcapng or classic pcap, so they open in Wireshark, tcpdump or whatever comes next in your pipeline.

Desktop app

A native window on macOS, Windows and Linux, with the menu bar, shortcuts and file dialogs you expect.

Local server

The same interface in your browser. Run ./pruftnet serve and open http://127.0.0.1:3000. It listens on localhost only.

Install

Running in a few minutes.

All downloads

macOS

macOS 15 or later, Apple Silicon or Intel.

  • Builds are not notarized yet. If macOS blocks the first launch, choose Open Anyway in System Settings › Privacy & Security.
  • Live capture needs access to /dev/bpf*. Wireshark’s ChmodBPF provides it, or grant it for the session:
sudo chown "$USER" /dev/bpf*
Download for macOS

Windows

Windows on x64.

  • Install Npcap first. Pruftnet uses it for capture and does not bundle it.
  • The installer is not signed yet, so Windows may show a publisher warning.
Download for Windows

Linux

Ubuntu 24.04+ or Debian 13+, x64 or ARM64.

  • Use the Debian package for live capture; AppImage cannot keep file capabilities.
  • Grant capture rights to the native worker only, never to the app itself:
sudo setcap cap_net_raw,cap_net_admin=eip /opt/Pruftnet/resources/native/pruftnet_capture_worker
Download for Linux