Repository files navigation

prt

See which processes own your network ports — live, from the terminal.

Crates.ioDownloadsCILicense: MITRust 1.75+API docs

English · Русский · 中文

prt is a keyboard-driven terminal UI for inspecting network connections, finding port conflicts, exploring process details, and managing SSH tunnels on macOS and Linux. It combines a live connection table with filtering, change tracking, process topology, alerts, and script-friendly output.

Demo

Animated prt demo moving from live connections to process details, network topology, the command palette, and contextual actions

The 13-second demo plays directly in the README. You can also view a static frame or read the demo transcript. The recording is reproducible from docs/demo.tape.

Quick start

Requirements

  • Rust 1.75 or newer for installation with Cargo
  • macOS 10.15 or newer with the built-in lsof
  • Linux with a mounted /proc filesystem
  • A UTF-8 terminal; a wider window gives the table more room

Install and run

cargo install prt
prt

Run sudo prt when the operating system hides processes owned by other users. Elevated privileges are not required for normal use.

To build the current source instead:

git clone https://github.com/rekurt/prt.git
cd prt
cargo install --path crates/prt

What you can do

TaskHow prt helps
Find a port conflictSearch by port, process, protocol, state, service, PID, or user
Follow connection changesRefresh every two seconds; new and closed entries are highlighted
Investigate a processInspect command line, parent tree, CPU, memory, open files, and related connections
Review network topologySee process → local port → remote endpoint as a terminal tree
Spot suspicious listenersFilter entries flagged with [!] by the built-in heuristics
Work with containersShow the owning Docker or Podman container when one is detected
Manage SSH forwardingRead hosts from SSH config and create, restart, edit, or save tunnels
Automate checksExport one snapshot as JSON/CSV or stream NDJSON continuously

prt also estimates system-wide bandwidth, maps common ports to service names, supports configurable alerts, and offers contextual actions for process termination, firewall blocking, copying, tracing, and SSH forwarding.

Command-line modes

prt # launch the interactive TUI
prt --lang ru # start in Russian (en, ru, or zh)
prt --export json # print one JSON snapshot and exit
prt --export csv # print one CSV snapshot and exit
prt --json # continuously stream NDJSON
prt watch 80 443 5432 # compact UP/DOWN monitor for selected ports
sudo prt # include processes hidden from the current user

Use --export for a finite snapshot. --json keeps running and emits one object per connection on each scan cycle; it stops cleanly when a downstream command such as head closes the pipe.

Examples:

# Save a snapshot for comparison or incident notes.
prt --export json > ports.json
# Show process names from the live stream.
prt --json | jq -r '.process.name'# Watch only development ports.
prt watch 3000 5432 8080

Interface guide

Tab and Shift+Tab move between three top-level sections:

SectionPurposeSub-tabs
ConnectionsSortable connection table and optional details panelNone
ProcessesDetails for the selected process and its network topologyDetail, Topology
SSHHosts loaded from SSH config and managed tunnelsHosts, Tunnels

Press ? at any time for the in-app cheat sheet. Press : to search the command palette when remembering a shortcut is inconvenient.

Keyboard reference

KeyAction
?Open the help screen; any key closes it
qQuit
Tab / Shift+TabNext / previous section
SpaceOpen the contextual action menu
:Open the searchable command palette
/Search and filter; press Esc twice to clear a non-empty filter
pPause or resume automatic refresh
rRefresh now
sEnter a sudo password when more process visibility is needed
LCycle the interface language
j / k, / Move or scroll
g / G, Home / EndJump to the beginning or end
K / DeleteAsk to terminate the selected process
cCopy the selected connection

Section-specific keys:

ContextKeyAction
ConnectionsEnterOpen the selected process in the Processes section
ConnectionsdShow or hide the bottom details panel
Connectionso / OChoose the next sort column / reverse sort direction
Processes[ / ]Switch between Detail and Topology
SSH[ / ]Switch between Hosts and Tunnels
SSH HostsEnterStart a tunnel form for the selected host
SSH HostsrReload SSH and prt configuration
SSH Tunnelsn / eCreate / edit a tunnel
SSH TunnelsK / r / sKill / restart / save tunnels

Search and change tracking

Type / to filter the live table. Plain text matches visible connection data; status aliases such as new, gone, and active can narrow the lifecycle state. Type ! or suspicious to show entries flagged by the suspicious-connection detector.

New entries are green. Closed entries are dimmed red and remain visible for five seconds. Connection state and age remain available as text, but the new/gone distinction is currently color-based.

Configuration

The optional configuration file is ~/.config/prt/config.toml. A missing file uses defaults; a parse error is reported and defaults are used.

# Add or override service names.
[known_ports]
3000 = "frontend"5432 = "postgres"# Ring the terminal bell for a new SSH connection.
[[alerts]]
port = 22action = "bell"# Highlight Python listeners.
[[alerts]]
process = "python"state = "LISTEN"action = "highlight"# Add a host alongside entries from ~/.ssh/config.
[[ssh_hosts]]
alias = "staging"hostname = "staging.example.com"user = "deploy"port = 22

Alert conditions are port, process, state, and connections_gt. Actions are bell and highlight. Bell alerts fire only for new entries.

The SSH section also reads ~/.ssh/config. Saved tunnels are written back to the [[ssh_tunnels]] section of the prt config by the Tunnels view.

Safety and permissions

Scanning and navigation are read-only. Actions that change system state are grouped in the Space menu:

  • Process termination asks you to choose SIGTERM or SIGKILL.
  • Firewall blocking shows a confirmation and requires suitable privileges.
  • System-call tracing requires ptrace permissions on Linux or suitable dtruss permissions on macOS.
  • SSH forwarding starts an ssh subprocess using the values shown in the tunnel form.

Review the confirmation or form before proceeding. See the security policy for vulnerability reporting and the supported release policy.

Documentation accessibility

  • The README begins with a copyable quick start and uses descriptive link text.
  • The demo has a non-animated preview, descriptive alternative text, and a text transcript.
  • The TUI is fully keyboard-driven and includes an in-app help screen and command palette.
  • English, Russian, and Chinese interfaces and READMEs are available.
  • Connection states and suspicious entries have text labels; new/gone lifecycle cues are currently color-based.
  • Non-interactive JSON, CSV, NDJSON, and watch modes provide alternatives to the full-screen TUI.

If the terminal interface itself is not usable with your assistive technology, prt --export json is the most predictable machine-readable alternative.

Architecture

The repository is a Rust workspace with two crates:

crates/
├── prt-core/ scanning, tracking, filtering, alerts, configuration,
│ process details, containers, i18n, and platform adapters
└── prt/ clap CLI, ratatui interface, input handling, streaming,
watch mode, tracing, and SSH tunnel management

The main refresh flow is:

platform scan
→ Session refresh
→ diff New / Unchanged / Gone entries
→ enrich services, suspicious flags, and containers
→ retain recently closed entries
→ sample bandwidth and sort
→ evaluate alerts, filter, and render

macOS scans structured lsof output and batches process metadata lookups. Linux reads /proc/net through the procfs crate.

Library users can read the prt-core API documentation. Contributors should start with CONTRIBUTING.md.

Development

cargo build --workspace
cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings
cargo fmt --all -- --check

License

Licensed under the MIT License.

If prt is useful to you, consider starring the project on GitHub.

About

Real-time terminal UI for monitoring network ports — interactive alternative to lsof, ss, netstat with TUI, alerts, firewall, strace, containers and process trees

Topics

Resources

Contributing

Security policy

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

prt

See which processes own your network ports — live, from the terminal.

Crates.ioDownloadsCILicense: MITRust 1.75+API docs

English · Русский · 中文

prt is a keyboard-driven terminal UI for inspecting network connections, finding port conflicts, exploring process details, and managing SSH tunnels on macOS and Linux. It combines a live connection table with filtering, change tracking, process topology, alerts, and script-friendly output.

Demo

Animated prt demo moving from live connections to process details, network topology, the command palette, and contextual actions

The 13-second demo plays directly in the README. You can also view a static frame or read the demo transcript. The recording is reproducible from docs/demo.tape.

Quick start

Requirements

  • Rust 1.75 or newer for installation with Cargo
  • macOS 10.15 or newer with the built-in lsof
  • Linux with a mounted /proc filesystem
  • A UTF-8 terminal; a wider window gives the table more room

Install and run

cargo install prt
prt

Run sudo prt when the operating system hides processes owned by other users. Elevated privileges are not required for normal use.

To build the current source instead:

git clone https://github.com/rekurt/prt.git
cd prt
cargo install --path crates/prt

What you can do

TaskHow prt helps
Find a port conflictSearch by port, process, protocol, state, service, PID, or user
Follow connection changesRefresh every two seconds; new and closed entries are highlighted
Investigate a processInspect command line, parent tree, CPU, memory, open files, and related connections
Review network topologySee process → local port → remote endpoint as a terminal tree
Spot suspicious listenersFilter entries flagged with [!] by the built-in heuristics
Work with containersShow the owning Docker or Podman container when one is detected
Manage SSH forwardingRead hosts from SSH config and create, restart, edit, or save tunnels
Automate checksExport one snapshot as JSON/CSV or stream NDJSON continuously

prt also estimates system-wide bandwidth, maps common ports to service names, supports configurable alerts, and offers contextual actions for process termination, firewall blocking, copying, tracing, and SSH forwarding.

Command-line modes

prt # launch the interactive TUI
prt --lang ru # start in Russian (en, ru, or zh)
prt --export json # print one JSON snapshot and exit
prt --export csv # print one CSV snapshot and exit
prt --json # continuously stream NDJSON
prt watch 80 443 5432 # compact UP/DOWN monitor for selected ports
sudo prt # include processes hidden from the current user

Use --export for a finite snapshot. --json keeps running and emits one object per connection on each scan cycle; it stops cleanly when a downstream command such as head closes the pipe.

Examples:

# Save a snapshot for comparison or incident notes.
prt --export json > ports.json
# Show process names from the live stream.
prt --json | jq -r '.process.name'# Watch only development ports.
prt watch 3000 5432 8080

Interface guide

Tab and Shift+Tab move between three top-level sections:

SectionPurposeSub-tabs
ConnectionsSortable connection table and optional details panelNone
ProcessesDetails for the selected process and its network topologyDetail, Topology
SSHHosts loaded from SSH config and managed tunnelsHosts, Tunnels

Press ? at any time for the in-app cheat sheet. Press : to search the command palette when remembering a shortcut is inconvenient.

Keyboard reference

KeyAction
?Open the help screen; any key closes it
qQuit
Tab / Shift+TabNext / previous section
SpaceOpen the contextual action menu
:Open the searchable command palette
/Search and filter; press Esc twice to clear a non-empty filter
pPause or resume automatic refresh
rRefresh now
sEnter a sudo password when more process visibility is needed
LCycle the interface language
j / k, / Move or scroll
g / G, Home / EndJump to the beginning or end
K / DeleteAsk to terminate the selected process
cCopy the selected connection

Section-specific keys:

ContextKeyAction
ConnectionsEnterOpen the selected process in the Processes section
ConnectionsdShow or hide the bottom details panel
Connectionso / OChoose the next sort column / reverse sort direction
Processes[ / ]Switch between Detail and Topology
SSH[ / ]Switch between Hosts and Tunnels
SSH HostsEnterStart a tunnel form for the selected host
SSH HostsrReload SSH and prt configuration
SSH Tunnelsn / eCreate / edit a tunnel
SSH TunnelsK / r / sKill / restart / save tunnels

Search and change tracking

Type / to filter the live table. Plain text matches visible connection data; status aliases such as new, gone, and active can narrow the lifecycle state. Type ! or suspicious to show entries flagged by the suspicious-connection detector.

New entries are green. Closed entries are dimmed red and remain visible for five seconds. Connection state and age remain available as text, but the new/gone distinction is currently color-based.

Configuration

The optional configuration file is ~/.config/prt/config.toml. A missing file uses defaults; a parse error is reported and defaults are used.

# Add or override service names.
[known_ports]
3000 = "frontend"5432 = "postgres"# Ring the terminal bell for a new SSH connection.
[[alerts]]
port = 22action = "bell"# Highlight Python listeners.
[[alerts]]
process = "python"state = "LISTEN"action = "highlight"# Add a host alongside entries from ~/.ssh/config.
[[ssh_hosts]]
alias = "staging"hostname = "staging.example.com"user = "deploy"port = 22

Alert conditions are port, process, state, and connections_gt. Actions are bell and highlight. Bell alerts fire only for new entries.

The SSH section also reads ~/.ssh/config. Saved tunnels are written back to the [[ssh_tunnels]] section of the prt config by the Tunnels view.

Safety and permissions

Scanning and navigation are read-only. Actions that change system state are grouped in the Space menu:

  • Process termination asks you to choose SIGTERM or SIGKILL.
  • Firewall blocking shows a confirmation and requires suitable privileges.
  • System-call tracing requires ptrace permissions on Linux or suitable dtruss permissions on macOS.
  • SSH forwarding starts an ssh subprocess using the values shown in the tunnel form.

Review the confirmation or form before proceeding. See the security policy for vulnerability reporting and the supported release policy.

Documentation accessibility

  • The README begins with a copyable quick start and uses descriptive link text.
  • The demo has a non-animated preview, descriptive alternative text, and a text transcript.
  • The TUI is fully keyboard-driven and includes an in-app help screen and command palette.
  • English, Russian, and Chinese interfaces and READMEs are available.
  • Connection states and suspicious entries have text labels; new/gone lifecycle cues are currently color-based.
  • Non-interactive JSON, CSV, NDJSON, and watch modes provide alternatives to the full-screen TUI.

If the terminal interface itself is not usable with your assistive technology, prt --export json is the most predictable machine-readable alternative.

Architecture

The repository is a Rust workspace with two crates:

crates/
├── prt-core/ scanning, tracking, filtering, alerts, configuration,
│ process details, containers, i18n, and platform adapters
└── prt/ clap CLI, ratatui interface, input handling, streaming,
watch mode, tracing, and SSH tunnel management

The main refresh flow is:

platform scan
→ Session refresh
→ diff New / Unchanged / Gone entries
→ enrich services, suspicious flags, and containers
→ retain recently closed entries
→ sample bandwidth and sort
→ evaluate alerts, filter, and render

macOS scans structured lsof output and batches process metadata lookups. Linux reads /proc/net through the procfs crate.

Library users can read the prt-core API documentation. Contributors should start with CONTRIBUTING.md.

Development

cargo build --workspace
cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings
cargo fmt --all -- --check

License

Licensed under the MIT License.

If prt is useful to you, consider starring the project on GitHub.

About

Real-time terminal UI for monitoring network ports — interactive alternative to lsof, ss, netstat with TUI, alerts, firewall, strace, containers and process trees

Topics

Resources

Contributing

Security policy

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

prt

See which processes own your network ports — live, from the terminal.

Crates.ioDownloadsCILicense: MITRust 1.75+API docs

English · Русский · 中文

prt is a keyboard-driven terminal UI for inspecting network connections, finding port conflicts, exploring process details, and managing SSH tunnels on macOS and Linux. It combines a live connection table with filtering, change tracking, process topology, alerts, and script-friendly output.

Demo

Animated prt demo moving from live connections to process details, network topology, the command palette, and contextual actions

The 13-second demo plays directly in the README. You can also view a static frame or read the demo transcript. The recording is reproducible from docs/demo.tape.

Quick start

Requirements

  • Rust 1.75 or newer for installation with Cargo
  • macOS 10.15 or newer with the built-in lsof
  • Linux with a mounted /proc filesystem
  • A UTF-8 terminal; a wider window gives the table more room

Install and run

cargo install prt
prt

Run sudo prt when the operating system hides processes owned by other users. Elevated privileges are not required for normal use.

To build the current source instead:

git clone https://github.com/rekurt/prt.git
cd prt
cargo install --path crates/prt

What you can do

TaskHow prt helps
Find a port conflictSearch by port, process, protocol, state, service, PID, or user
Follow connection changesRefresh every two seconds; new and closed entries are highlighted
Investigate a processInspect command line, parent tree, CPU, memory, open files, and related connections
Review network topologySee process → local port → remote endpoint as a terminal tree
Spot suspicious listenersFilter entries flagged with [!] by the built-in heuristics
Work with containersShow the owning Docker or Podman container when one is detected
Manage SSH forwardingRead hosts from SSH config and create, restart, edit, or save tunnels
Automate checksExport one snapshot as JSON/CSV or stream NDJSON continuously

prt also estimates system-wide bandwidth, maps common ports to service names, supports configurable alerts, and offers contextual actions for process termination, firewall blocking, copying, tracing, and SSH forwarding.

Command-line modes

prt # launch the interactive TUI
prt --lang ru # start in Russian (en, ru, or zh)
prt --export json # print one JSON snapshot and exit
prt --export csv # print one CSV snapshot and exit
prt --json # continuously stream NDJSON
prt watch 80 443 5432 # compact UP/DOWN monitor for selected ports
sudo prt # include processes hidden from the current user

Use --export for a finite snapshot. --json keeps running and emits one object per connection on each scan cycle; it stops cleanly when a downstream command such as head closes the pipe.

Examples:

# Save a snapshot for comparison or incident notes.
prt --export json > ports.json
# Show process names from the live stream.
prt --json | jq -r '.process.name'# Watch only development ports.
prt watch 3000 5432 8080

Interface guide

Tab and Shift+Tab move between three top-level sections:

SectionPurposeSub-tabs
ConnectionsSortable connection table and optional details panelNone
ProcessesDetails for the selected process and its network topologyDetail, Topology
SSHHosts loaded from SSH config and managed tunnelsHosts, Tunnels

Press ? at any time for the in-app cheat sheet. Press : to search the command palette when remembering a shortcut is inconvenient.

Keyboard reference

KeyAction
?Open the help screen; any key closes it
qQuit
Tab / Shift+TabNext / previous section
SpaceOpen the contextual action menu
:Open the searchable command palette
/Search and filter; press Esc twice to clear a non-empty filter
pPause or resume automatic refresh
rRefresh now
sEnter a sudo password when more process visibility is needed
LCycle the interface language
j / k, / Move or scroll
g / G, Home / EndJump to the beginning or end
K / DeleteAsk to terminate the selected process
cCopy the selected connection

Section-specific keys:

ContextKeyAction
ConnectionsEnterOpen the selected process in the Processes section
ConnectionsdShow or hide the bottom details panel
Connectionso / OChoose the next sort column / reverse sort direction
Processes[ / ]Switch between Detail and Topology
SSH[ / ]Switch between Hosts and Tunnels
SSH HostsEnterStart a tunnel form for the selected host
SSH HostsrReload SSH and prt configuration
SSH Tunnelsn / eCreate / edit a tunnel
SSH TunnelsK / r / sKill / restart / save tunnels

Search and change tracking

Type / to filter the live table. Plain text matches visible connection data; status aliases such as new, gone, and active can narrow the lifecycle state. Type ! or suspicious to show entries flagged by the suspicious-connection detector.

New entries are green. Closed entries are dimmed red and remain visible for five seconds. Connection state and age remain available as text, but the new/gone distinction is currently color-based.

Configuration

The optional configuration file is ~/.config/prt/config.toml. A missing file uses defaults; a parse error is reported and defaults are used.

# Add or override service names.
[known_ports]
3000 = "frontend"5432 = "postgres"# Ring the terminal bell for a new SSH connection.
[[alerts]]
port = 22action = "bell"# Highlight Python listeners.
[[alerts]]
process = "python"state = "LISTEN"action = "highlight"# Add a host alongside entries from ~/.ssh/config.
[[ssh_hosts]]
alias = "staging"hostname = "staging.example.com"user = "deploy"port = 22

Alert conditions are port, process, state, and connections_gt. Actions are bell and highlight. Bell alerts fire only for new entries.

The SSH section also reads ~/.ssh/config. Saved tunnels are written back to the [[ssh_tunnels]] section of the prt config by the Tunnels view.

Safety and permissions

Scanning and navigation are read-only. Actions that change system state are grouped in the Space menu:

  • Process termination asks you to choose SIGTERM or SIGKILL.
  • Firewall blocking shows a confirmation and requires suitable privileges.
  • System-call tracing requires ptrace permissions on Linux or suitable dtruss permissions on macOS.
  • SSH forwarding starts an ssh subprocess using the values shown in the tunnel form.

Review the confirmation or form before proceeding. See the security policy for vulnerability reporting and the supported release policy.

Documentation accessibility

  • The README begins with a copyable quick start and uses descriptive link text.
  • The demo has a non-animated preview, descriptive alternative text, and a text transcript.
  • The TUI is fully keyboard-driven and includes an in-app help screen and command palette.
  • English, Russian, and Chinese interfaces and READMEs are available.
  • Connection states and suspicious entries have text labels; new/gone lifecycle cues are currently color-based.
  • Non-interactive JSON, CSV, NDJSON, and watch modes provide alternatives to the full-screen TUI.

If the terminal interface itself is not usable with your assistive technology, prt --export json is the most predictable machine-readable alternative.

Architecture

The repository is a Rust workspace with two crates:

crates/
├── prt-core/ scanning, tracking, filtering, alerts, configuration,
│ process details, containers, i18n, and platform adapters
└── prt/ clap CLI, ratatui interface, input handling, streaming,
watch mode, tracing, and SSH tunnel management

The main refresh flow is:

platform scan
→ Session refresh
→ diff New / Unchanged / Gone entries
→ enrich services, suspicious flags, and containers
→ retain recently closed entries
→ sample bandwidth and sort
→ evaluate alerts, filter, and render

macOS scans structured lsof output and batches process metadata lookups. Linux reads /proc/net through the procfs crate.

Library users can read the prt-core API documentation. Contributors should start with CONTRIBUTING.md.

Development

cargo build --workspace
cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings
cargo fmt --all -- --check

License

Licensed under the MIT License.

If prt is useful to you, consider starring the project on GitHub.

About

Real-time terminal UI for monitoring network ports — interactive alternative to lsof, ss, netstat with TUI, alerts, firewall, strace, containers and process trees

Topics

Resources

Contributing

Security policy

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

prt

See which processes own your network ports — live, from the terminal.

Crates.ioDownloadsCILicense: MITRust 1.75+API docs

English · Русский · 中文

prt is a keyboard-driven terminal UI for inspecting network connections, finding port conflicts, exploring process details, and managing SSH tunnels on macOS and Linux. It combines a live connection table with filtering, change tracking, process topology, alerts, and script-friendly output.

Demo

Animated prt demo moving from live connections to process details, network topology, the command palette, and contextual actions

The 13-second demo plays directly in the README. You can also view a static frame or read the demo transcript. The recording is reproducible from docs/demo.tape.

Quick start

Requirements

  • Rust 1.75 or newer for installation with Cargo
  • macOS 10.15 or newer with the built-in lsof
  • Linux with a mounted /proc filesystem
  • A UTF-8 terminal; a wider window gives the table more room

Install and run

cargo install prt
prt

Run sudo prt when the operating system hides processes owned by other users. Elevated privileges are not required for normal use.

To build the current source instead:

git clone https://github.com/rekurt/prt.git
cd prt
cargo install --path crates/prt

What you can do

TaskHow prt helps
Find a port conflictSearch by port, process, protocol, state, service, PID, or user
Follow connection changesRefresh every two seconds; new and closed entries are highlighted
Investigate a processInspect command line, parent tree, CPU, memory, open files, and related connections
Review network topologySee process → local port → remote endpoint as a terminal tree
Spot suspicious listenersFilter entries flagged with [!] by the built-in heuristics
Work with containersShow the owning Docker or Podman container when one is detected
Manage SSH forwardingRead hosts from SSH config and create, restart, edit, or save tunnels
Automate checksExport one snapshot as JSON/CSV or stream NDJSON continuously

prt also estimates system-wide bandwidth, maps common ports to service names, supports configurable alerts, and offers contextual actions for process termination, firewall blocking, copying, tracing, and SSH forwarding.

Command-line modes

prt # launch the interactive TUI
prt --lang ru # start in Russian (en, ru, or zh)
prt --export json # print one JSON snapshot and exit
prt --export csv # print one CSV snapshot and exit
prt --json # continuously stream NDJSON
prt watch 80 443 5432 # compact UP/DOWN monitor for selected ports
sudo prt # include processes hidden from the current user

Use --export for a finite snapshot. --json keeps running and emits one object per connection on each scan cycle; it stops cleanly when a downstream command such as head closes the pipe.

Examples:

# Save a snapshot for comparison or incident notes.
prt --export json > ports.json
# Show process names from the live stream.
prt --json | jq -r '.process.name'# Watch only development ports.
prt watch 3000 5432 8080

Interface guide

Tab and Shift+Tab move between three top-level sections:

SectionPurposeSub-tabs
ConnectionsSortable connection table and optional details panelNone
ProcessesDetails for the selected process and its network topologyDetail, Topology
SSHHosts loaded from SSH config and managed tunnelsHosts, Tunnels

Press ? at any time for the in-app cheat sheet. Press : to search the command palette when remembering a shortcut is inconvenient.

Keyboard reference

KeyAction
?Open the help screen; any key closes it
qQuit
Tab / Shift+TabNext / previous section
SpaceOpen the contextual action menu
:Open the searchable command palette
/Search and filter; press Esc twice to clear a non-empty filter
pPause or resume automatic refresh
rRefresh now
sEnter a sudo password when more process visibility is needed
LCycle the interface language
j / k, / Move or scroll
g / G, Home / EndJump to the beginning or end
K / DeleteAsk to terminate the selected process
cCopy the selected connection

Section-specific keys:

ContextKeyAction
ConnectionsEnterOpen the selected process in the Processes section
ConnectionsdShow or hide the bottom details panel
Connectionso / OChoose the next sort column / reverse sort direction
Processes[ / ]Switch between Detail and Topology
SSH[ / ]Switch between Hosts and Tunnels
SSH HostsEnterStart a tunnel form for the selected host
SSH HostsrReload SSH and prt configuration
SSH Tunnelsn / eCreate / edit a tunnel
SSH TunnelsK / r / sKill / restart / save tunnels

Search and change tracking

Type / to filter the live table. Plain text matches visible connection data; status aliases such as new, gone, and active can narrow the lifecycle state. Type ! or suspicious to show entries flagged by the suspicious-connection detector.

New entries are green. Closed entries are dimmed red and remain visible for five seconds. Connection state and age remain available as text, but the new/gone distinction is currently color-based.

Configuration

The optional configuration file is ~/.config/prt/config.toml. A missing file uses defaults; a parse error is reported and defaults are used.

# Add or override service names.
[known_ports]
3000 = "frontend"5432 = "postgres"# Ring the terminal bell for a new SSH connection.
[[alerts]]
port = 22action = "bell"# Highlight Python listeners.
[[alerts]]
process = "python"state = "LISTEN"action = "highlight"# Add a host alongside entries from ~/.ssh/config.
[[ssh_hosts]]
alias = "staging"hostname = "staging.example.com"user = "deploy"port = 22

Alert conditions are port, process, state, and connections_gt. Actions are bell and highlight. Bell alerts fire only for new entries.

The SSH section also reads ~/.ssh/config. Saved tunnels are written back to the [[ssh_tunnels]] section of the prt config by the Tunnels view.

Safety and permissions

Scanning and navigation are read-only. Actions that change system state are grouped in the Space menu:

  • Process termination asks you to choose SIGTERM or SIGKILL.
  • Firewall blocking shows a confirmation and requires suitable privileges.
  • System-call tracing requires ptrace permissions on Linux or suitable dtruss permissions on macOS.
  • SSH forwarding starts an ssh subprocess using the values shown in the tunnel form.

Review the confirmation or form before proceeding. See the security policy for vulnerability reporting and the supported release policy.

Documentation accessibility

  • The README begins with a copyable quick start and uses descriptive link text.
  • The demo has a non-animated preview, descriptive alternative text, and a text transcript.
  • The TUI is fully keyboard-driven and includes an in-app help screen and command palette.
  • English, Russian, and Chinese interfaces and READMEs are available.
  • Connection states and suspicious entries have text labels; new/gone lifecycle cues are currently color-based.
  • Non-interactive JSON, CSV, NDJSON, and watch modes provide alternatives to the full-screen TUI.

If the terminal interface itself is not usable with your assistive technology, prt --export json is the most predictable machine-readable alternative.

Architecture

The repository is a Rust workspace with two crates:

crates/
├── prt-core/ scanning, tracking, filtering, alerts, configuration,
│ process details, containers, i18n, and platform adapters
└── prt/ clap CLI, ratatui interface, input handling, streaming,
watch mode, tracing, and SSH tunnel management

The main refresh flow is:

platform scan
→ Session refresh
→ diff New / Unchanged / Gone entries
→ enrich services, suspicious flags, and containers
→ retain recently closed entries
→ sample bandwidth and sort
→ evaluate alerts, filter, and render

macOS scans structured lsof output and batches process metadata lookups. Linux reads /proc/net through the procfs crate.

Library users can read the prt-core API documentation. Contributors should start with CONTRIBUTING.md.

Development

cargo build --workspace
cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings
cargo fmt --all -- --check

License

Licensed under the MIT License.

If prt is useful to you, consider starring the project on GitHub.

About

Real-time terminal UI for monitoring network ports — interactive alternative to lsof, ss, netstat with TUI, alerts, firewall, strace, containers and process trees

Topics

Resources

Contributing

Security policy

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

prt

See which processes own your network ports — live, from the terminal.

Crates.ioDownloadsCILicense: MITRust 1.75+API docs

English · Русский · 中文

prt is a keyboard-driven terminal UI for inspecting network connections, finding port conflicts, exploring process details, and managing SSH tunnels on macOS and Linux. It combines a live connection table with filtering, change tracking, process topology, alerts, and script-friendly output.

Demo

Animated prt demo moving from live connections to process details, network topology, the command palette, and contextual actions

The 13-second demo plays directly in the README. You can also view a static frame or read the demo transcript. The recording is reproducible from docs/demo.tape.

Quick start

Requirements

  • Rust 1.75 or newer for installation with Cargo
  • macOS 10.15 or newer with the built-in lsof
  • Linux with a mounted /proc filesystem
  • A UTF-8 terminal; a wider window gives the table more room

Install and run

cargo install prt
prt

Run sudo prt when the operating system hides processes owned by other users. Elevated privileges are not required for normal use.

To build the current source instead:

git clone https://github.com/rekurt/prt.git
cd prt
cargo install --path crates/prt

What you can do

TaskHow prt helps
Find a port conflictSearch by port, process, protocol, state, service, PID, or user
Follow connection changesRefresh every two seconds; new and closed entries are highlighted
Investigate a processInspect command line, parent tree, CPU, memory, open files, and related connections
Review network topologySee process → local port → remote endpoint as a terminal tree
Spot suspicious listenersFilter entries flagged with [!] by the built-in heuristics
Work with containersShow the owning Docker or Podman container when one is detected
Manage SSH forwardingRead hosts from SSH config and create, restart, edit, or save tunnels
Automate checksExport one snapshot as JSON/CSV or stream NDJSON continuously

prt also estimates system-wide bandwidth, maps common ports to service names, supports configurable alerts, and offers contextual actions for process termination, firewall blocking, copying, tracing, and SSH forwarding.

Command-line modes

prt # launch the interactive TUI
prt --lang ru # start in Russian (en, ru, or zh)
prt --export json # print one JSON snapshot and exit
prt --export csv # print one CSV snapshot and exit
prt --json # continuously stream NDJSON
prt watch 80 443 5432 # compact UP/DOWN monitor for selected ports
sudo prt # include processes hidden from the current user

Use --export for a finite snapshot. --json keeps running and emits one object per connection on each scan cycle; it stops cleanly when a downstream command such as head closes the pipe.

Examples:

# Save a snapshot for comparison or incident notes.
prt --export json > ports.json
# Show process names from the live stream.
prt --json | jq -r '.process.name'# Watch only development ports.
prt watch 3000 5432 8080

Interface guide

Tab and Shift+Tab move between three top-level sections:

SectionPurposeSub-tabs
ConnectionsSortable connection table and optional details panelNone
ProcessesDetails for the selected process and its network topologyDetail, Topology
SSHHosts loaded from SSH config and managed tunnelsHosts, Tunnels

Press ? at any time for the in-app cheat sheet. Press : to search the command palette when remembering a shortcut is inconvenient.

Keyboard reference

KeyAction
?Open the help screen; any key closes it
qQuit
Tab / Shift+TabNext / previous section
SpaceOpen the contextual action menu
:Open the searchable command palette
/Search and filter; press Esc twice to clear a non-empty filter
pPause or resume automatic refresh
rRefresh now
sEnter a sudo password when more process visibility is needed
LCycle the interface language
j / k, / Move or scroll
g / G, Home / EndJump to the beginning or end
K / DeleteAsk to terminate the selected process
cCopy the selected connection

Section-specific keys:

ContextKeyAction
ConnectionsEnterOpen the selected process in the Processes section
ConnectionsdShow or hide the bottom details panel
Connectionso / OChoose the next sort column / reverse sort direction
Processes[ / ]Switch between Detail and Topology
SSH[ / ]Switch between Hosts and Tunnels
SSH HostsEnterStart a tunnel form for the selected host
SSH HostsrReload SSH and prt configuration
SSH Tunnelsn / eCreate / edit a tunnel
SSH TunnelsK / r / sKill / restart / save tunnels

Search and change tracking

Type / to filter the live table. Plain text matches visible connection data; status aliases such as new, gone, and active can narrow the lifecycle state. Type ! or suspicious to show entries flagged by the suspicious-connection detector.

New entries are green. Closed entries are dimmed red and remain visible for five seconds. Connection state and age remain available as text, but the new/gone distinction is currently color-based.

Configuration

The optional configuration file is ~/.config/prt/config.toml. A missing file uses defaults; a parse error is reported and defaults are used.

# Add or override service names.
[known_ports]
3000 = "frontend"5432 = "postgres"# Ring the terminal bell for a new SSH connection.
[[alerts]]
port = 22action = "bell"# Highlight Python listeners.
[[alerts]]
process = "python"state = "LISTEN"action = "highlight"# Add a host alongside entries from ~/.ssh/config.
[[ssh_hosts]]
alias = "staging"hostname = "staging.example.com"user = "deploy"port = 22

Alert conditions are port, process, state, and connections_gt. Actions are bell and highlight. Bell alerts fire only for new entries.

The SSH section also reads ~/.ssh/config. Saved tunnels are written back to the [[ssh_tunnels]] section of the prt config by the Tunnels view.

Safety and permissions

Scanning and navigation are read-only. Actions that change system state are grouped in the Space menu:

  • Process termination asks you to choose SIGTERM or SIGKILL.
  • Firewall blocking shows a confirmation and requires suitable privileges.
  • System-call tracing requires ptrace permissions on Linux or suitable dtruss permissions on macOS.
  • SSH forwarding starts an ssh subprocess using the values shown in the tunnel form.

Review the confirmation or form before proceeding. See the security policy for vulnerability reporting and the supported release policy.

Documentation accessibility

  • The README begins with a copyable quick start and uses descriptive link text.
  • The demo has a non-animated preview, descriptive alternative text, and a text transcript.
  • The TUI is fully keyboard-driven and includes an in-app help screen and command palette.
  • English, Russian, and Chinese interfaces and READMEs are available.
  • Connection states and suspicious entries have text labels; new/gone lifecycle cues are currently color-based.
  • Non-interactive JSON, CSV, NDJSON, and watch modes provide alternatives to the full-screen TUI.

If the terminal interface itself is not usable with your assistive technology, prt --export json is the most predictable machine-readable alternative.

Architecture

The repository is a Rust workspace with two crates:

crates/
├── prt-core/ scanning, tracking, filtering, alerts, configuration,
│ process details, containers, i18n, and platform adapters
└── prt/ clap CLI, ratatui interface, input handling, streaming,
watch mode, tracing, and SSH tunnel management

The main refresh flow is:

platform scan
→ Session refresh
→ diff New / Unchanged / Gone entries
→ enrich services, suspicious flags, and containers
→ retain recently closed entries
→ sample bandwidth and sort
→ evaluate alerts, filter, and render

macOS scans structured lsof output and batches process metadata lookups. Linux reads /proc/net through the procfs crate.

Library users can read the prt-core API documentation. Contributors should start with CONTRIBUTING.md.

Development

cargo build --workspace
cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings
cargo fmt --all -- --check

License

Licensed under the MIT License.

If prt is useful to you, consider starring the project on GitHub.

About

Real-time terminal UI for monitoring network ports — interactive alternative to lsof, ss, netstat with TUI, alerts, firewall, strace, containers and process trees

Topics

Resources

Contributing

Security policy

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

prt

See which processes own your network ports — live, from the terminal.

Crates.ioDownloadsCILicense: MITRust 1.75+API docs

English · Русский · 中文

prt is a keyboard-driven terminal UI for inspecting network connections, finding port conflicts, exploring process details, and managing SSH tunnels on macOS and Linux. It combines a live connection table with filtering, change tracking, process topology, alerts, and script-friendly output.

Demo

Animated prt demo moving from live connections to process details, network topology, the command palette, and contextual actions

The 13-second demo plays directly in the README. You can also view a static frame or read the demo transcript. The recording is reproducible from docs/demo.tape.

Quick start

Requirements

  • Rust 1.75 or newer for installation with Cargo
  • macOS 10.15 or newer with the built-in lsof
  • Linux with a mounted /proc filesystem
  • A UTF-8 terminal; a wider window gives the table more room

Install and run

cargo install prt
prt

Run sudo prt when the operating system hides processes owned by other users. Elevated privileges are not required for normal use.

To build the current source instead:

git clone https://github.com/rekurt/prt.git
cd prt
cargo install --path crates/prt

What you can do

TaskHow prt helps
Find a port conflictSearch by port, process, protocol, state, service, PID, or user
Follow connection changesRefresh every two seconds; new and closed entries are highlighted
Investigate a processInspect command line, parent tree, CPU, memory, open files, and related connections
Review network topologySee process → local port → remote endpoint as a terminal tree
Spot suspicious listenersFilter entries flagged with [!] by the built-in heuristics
Work with containersShow the owning Docker or Podman container when one is detected
Manage SSH forwardingRead hosts from SSH config and create, restart, edit, or save tunnels
Automate checksExport one snapshot as JSON/CSV or stream NDJSON continuously

prt also estimates system-wide bandwidth, maps common ports to service names, supports configurable alerts, and offers contextual actions for process termination, firewall blocking, copying, tracing, and SSH forwarding.

Command-line modes

prt # launch the interactive TUI
prt --lang ru # start in Russian (en, ru, or zh)
prt --export json # print one JSON snapshot and exit
prt --export csv # print one CSV snapshot and exit
prt --json # continuously stream NDJSON
prt watch 80 443 5432 # compact UP/DOWN monitor for selected ports
sudo prt # include processes hidden from the current user

Use --export for a finite snapshot. --json keeps running and emits one object per connection on each scan cycle; it stops cleanly when a downstream command such as head closes the pipe.

Examples:

# Save a snapshot for comparison or incident notes.
prt --export json > ports.json
# Show process names from the live stream.
prt --json | jq -r '.process.name'# Watch only development ports.
prt watch 3000 5432 8080

Interface guide

Tab and Shift+Tab move between three top-level sections:

SectionPurposeSub-tabs
ConnectionsSortable connection table and optional details panelNone
ProcessesDetails for the selected process and its network topologyDetail, Topology
SSHHosts loaded from SSH config and managed tunnelsHosts, Tunnels

Press ? at any time for the in-app cheat sheet. Press : to search the command palette when remembering a shortcut is inconvenient.

Keyboard reference

KeyAction
?Open the help screen; any key closes it
qQuit
Tab / Shift+TabNext / previous section
SpaceOpen the contextual action menu
:Open the searchable command palette
/Search and filter; press Esc twice to clear a non-empty filter
pPause or resume automatic refresh
rRefresh now
sEnter a sudo password when more process visibility is needed
LCycle the interface language
j / k, / Move or scroll
g / G, Home / EndJump to the beginning or end
K / DeleteAsk to terminate the selected process
cCopy the selected connection

Section-specific keys:

ContextKeyAction
ConnectionsEnterOpen the selected process in the Processes section
ConnectionsdShow or hide the bottom details panel
Connectionso / OChoose the next sort column / reverse sort direction
Processes[ / ]Switch between Detail and Topology
SSH[ / ]Switch between Hosts and Tunnels
SSH HostsEnterStart a tunnel form for the selected host
SSH HostsrReload SSH and prt configuration
SSH Tunnelsn / eCreate / edit a tunnel
SSH TunnelsK / r / sKill / restart / save tunnels

Search and change tracking

Type / to filter the live table. Plain text matches visible connection data; status aliases such as new, gone, and active can narrow the lifecycle state. Type ! or suspicious to show entries flagged by the suspicious-connection detector.

New entries are green. Closed entries are dimmed red and remain visible for five seconds. Connection state and age remain available as text, but the new/gone distinction is currently color-based.

Configuration

The optional configuration file is ~/.config/prt/config.toml. A missing file uses defaults; a parse error is reported and defaults are used.

# Add or override service names.
[known_ports]
3000 = "frontend"5432 = "postgres"# Ring the terminal bell for a new SSH connection.
[[alerts]]
port = 22action = "bell"# Highlight Python listeners.
[[alerts]]
process = "python"state = "LISTEN"action = "highlight"# Add a host alongside entries from ~/.ssh/config.
[[ssh_hosts]]
alias = "staging"hostname = "staging.example.com"user = "deploy"port = 22

Alert conditions are port, process, state, and connections_gt. Actions are bell and highlight. Bell alerts fire only for new entries.

The SSH section also reads ~/.ssh/config. Saved tunnels are written back to the [[ssh_tunnels]] section of the prt config by the Tunnels view.

Safety and permissions

Scanning and navigation are read-only. Actions that change system state are grouped in the Space menu:

  • Process termination asks you to choose SIGTERM or SIGKILL.
  • Firewall blocking shows a confirmation and requires suitable privileges.
  • System-call tracing requires ptrace permissions on Linux or suitable dtruss permissions on macOS.
  • SSH forwarding starts an ssh subprocess using the values shown in the tunnel form.

Review the confirmation or form before proceeding. See the security policy for vulnerability reporting and the supported release policy.

Documentation accessibility

  • The README begins with a copyable quick start and uses descriptive link text.
  • The demo has a non-animated preview, descriptive alternative text, and a text transcript.
  • The TUI is fully keyboard-driven and includes an in-app help screen and command palette.
  • English, Russian, and Chinese interfaces and READMEs are available.
  • Connection states and suspicious entries have text labels; new/gone lifecycle cues are currently color-based.
  • Non-interactive JSON, CSV, NDJSON, and watch modes provide alternatives to the full-screen TUI.

If the terminal interface itself is not usable with your assistive technology, prt --export json is the most predictable machine-readable alternative.

Architecture

The repository is a Rust workspace with two crates:

crates/
├── prt-core/ scanning, tracking, filtering, alerts, configuration,
│ process details, containers, i18n, and platform adapters
└── prt/ clap CLI, ratatui interface, input handling, streaming,
watch mode, tracing, and SSH tunnel management

The main refresh flow is:

platform scan
→ Session refresh
→ diff New / Unchanged / Gone entries
→ enrich services, suspicious flags, and containers
→ retain recently closed entries
→ sample bandwidth and sort
→ evaluate alerts, filter, and render

macOS scans structured lsof output and batches process metadata lookups. Linux reads /proc/net through the procfs crate.

Library users can read the prt-core API documentation. Contributors should start with CONTRIBUTING.md.

Development

cargo build --workspace
cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings
cargo fmt --all -- --check

License

Licensed under the MIT License.

If prt is useful to you, consider starring the project on GitHub.

About

Real-time terminal UI for monitoring network ports — interactive alternative to lsof, ss, netstat with TUI, alerts, firewall, strace, containers and process trees

Topics

Resources

Contributing

Security policy

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

prt

See which processes own your network ports — live, from the terminal.

Crates.ioDownloadsCILicense: MITRust 1.75+API docs

English · Русский · 中文

prt is a keyboard-driven terminal UI for inspecting network connections, finding port conflicts, exploring process details, and managing SSH tunnels on macOS and Linux. It combines a live connection table with filtering, change tracking, process topology, alerts, and script-friendly output.

Demo

Animated prt demo moving from live connections to process details, network topology, the command palette, and contextual actions

The 13-second demo plays directly in the README. You can also view a static frame or read the demo transcript. The recording is reproducible from docs/demo.tape.

Quick start

Requirements

  • Rust 1.75 or newer for installation with Cargo
  • macOS 10.15 or newer with the built-in lsof
  • Linux with a mounted /proc filesystem
  • A UTF-8 terminal; a wider window gives the table more room

Install and run

cargo install prt
prt

Run sudo prt when the operating system hides processes owned by other users. Elevated privileges are not required for normal use.

To build the current source instead:

git clone https://github.com/rekurt/prt.git
cd prt
cargo install --path crates/prt

What you can do

TaskHow prt helps
Find a port conflictSearch by port, process, protocol, state, service, PID, or user
Follow connection changesRefresh every two seconds; new and closed entries are highlighted
Investigate a processInspect command line, parent tree, CPU, memory, open files, and related connections
Review network topologySee process → local port → remote endpoint as a terminal tree
Spot suspicious listenersFilter entries flagged with [!] by the built-in heuristics
Work with containersShow the owning Docker or Podman container when one is detected
Manage SSH forwardingRead hosts from SSH config and create, restart, edit, or save tunnels
Automate checksExport one snapshot as JSON/CSV or stream NDJSON continuously

prt also estimates system-wide bandwidth, maps common ports to service names, supports configurable alerts, and offers contextual actions for process termination, firewall blocking, copying, tracing, and SSH forwarding.

Command-line modes

prt # launch the interactive TUI
prt --lang ru # start in Russian (en, ru, or zh)
prt --export json # print one JSON snapshot and exit
prt --export csv # print one CSV snapshot and exit
prt --json # continuously stream NDJSON
prt watch 80 443 5432 # compact UP/DOWN monitor for selected ports
sudo prt # include processes hidden from the current user

Use --export for a finite snapshot. --json keeps running and emits one object per connection on each scan cycle; it stops cleanly when a downstream command such as head closes the pipe.

Examples:

# Save a snapshot for comparison or incident notes.
prt --export json > ports.json
# Show process names from the live stream.
prt --json | jq -r '.process.name'# Watch only development ports.
prt watch 3000 5432 8080

Interface guide

Tab and Shift+Tab move between three top-level sections:

SectionPurposeSub-tabs
ConnectionsSortable connection table and optional details panelNone
ProcessesDetails for the selected process and its network topologyDetail, Topology
SSHHosts loaded from SSH config and managed tunnelsHosts, Tunnels

Press ? at any time for the in-app cheat sheet. Press : to search the command palette when remembering a shortcut is inconvenient.

Keyboard reference

KeyAction
?Open the help screen; any key closes it
qQuit
Tab / Shift+TabNext / previous section
SpaceOpen the contextual action menu
:Open the searchable command palette
/Search and filter; press Esc twice to clear a non-empty filter
pPause or resume automatic refresh
rRefresh now
sEnter a sudo password when more process visibility is needed
LCycle the interface language
j / k, / Move or scroll
g / G, Home / EndJump to the beginning or end
K / DeleteAsk to terminate the selected process
cCopy the selected connection

Section-specific keys:

ContextKeyAction
ConnectionsEnterOpen the selected process in the Processes section
ConnectionsdShow or hide the bottom details panel
Connectionso / OChoose the next sort column / reverse sort direction
Processes[ / ]Switch between Detail and Topology
SSH[ / ]Switch between Hosts and Tunnels
SSH HostsEnterStart a tunnel form for the selected host
SSH HostsrReload SSH and prt configuration
SSH Tunnelsn / eCreate / edit a tunnel
SSH TunnelsK / r / sKill / restart / save tunnels

Search and change tracking

Type / to filter the live table. Plain text matches visible connection data; status aliases such as new, gone, and active can narrow the lifecycle state. Type ! or suspicious to show entries flagged by the suspicious-connection detector.

New entries are green. Closed entries are dimmed red and remain visible for five seconds. Connection state and age remain available as text, but the new/gone distinction is currently color-based.

Configuration

The optional configuration file is ~/.config/prt/config.toml. A missing file uses defaults; a parse error is reported and defaults are used.

# Add or override service names.
[known_ports]
3000 = "frontend"5432 = "postgres"# Ring the terminal bell for a new SSH connection.
[[alerts]]
port = 22action = "bell"# Highlight Python listeners.
[[alerts]]
process = "python"state = "LISTEN"action = "highlight"# Add a host alongside entries from ~/.ssh/config.
[[ssh_hosts]]
alias = "staging"hostname = "staging.example.com"user = "deploy"port = 22

Alert conditions are port, process, state, and connections_gt. Actions are bell and highlight. Bell alerts fire only for new entries.

The SSH section also reads ~/.ssh/config. Saved tunnels are written back to the [[ssh_tunnels]] section of the prt config by the Tunnels view.

Safety and permissions

Scanning and navigation are read-only. Actions that change system state are grouped in the Space menu:

  • Process termination asks you to choose SIGTERM or SIGKILL.
  • Firewall blocking shows a confirmation and requires suitable privileges.
  • System-call tracing requires ptrace permissions on Linux or suitable dtruss permissions on macOS.
  • SSH forwarding starts an ssh subprocess using the values shown in the tunnel form.

Review the confirmation or form before proceeding. See the security policy for vulnerability reporting and the supported release policy.

Documentation accessibility

  • The README begins with a copyable quick start and uses descriptive link text.
  • The demo has a non-animated preview, descriptive alternative text, and a text transcript.
  • The TUI is fully keyboard-driven and includes an in-app help screen and command palette.
  • English, Russian, and Chinese interfaces and READMEs are available.
  • Connection states and suspicious entries have text labels; new/gone lifecycle cues are currently color-based.
  • Non-interactive JSON, CSV, NDJSON, and watch modes provide alternatives to the full-screen TUI.

If the terminal interface itself is not usable with your assistive technology, prt --export json is the most predictable machine-readable alternative.

Architecture

The repository is a Rust workspace with two crates:

crates/
├── prt-core/ scanning, tracking, filtering, alerts, configuration,
│ process details, containers, i18n, and platform adapters
└── prt/ clap CLI, ratatui interface, input handling, streaming,
watch mode, tracing, and SSH tunnel management

The main refresh flow is:

platform scan
→ Session refresh
→ diff New / Unchanged / Gone entries
→ enrich services, suspicious flags, and containers
→ retain recently closed entries
→ sample bandwidth and sort
→ evaluate alerts, filter, and render

macOS scans structured lsof output and batches process metadata lookups. Linux reads /proc/net through the procfs crate.

Library users can read the prt-core API documentation. Contributors should start with CONTRIBUTING.md.

Development

cargo build --workspace
cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings
cargo fmt --all -- --check

License

Licensed under the MIT License.

If prt is useful to you, consider starring the project on GitHub.

About

Real-time terminal UI for monitoring network ports — interactive alternative to lsof, ss, netstat with TUI, alerts, firewall, strace, containers and process trees

Topics

Resources

Contributing

Security policy

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

prt

See which processes own your network ports — live, from the terminal.

Crates.ioDownloadsCILicense: MITRust 1.75+API docs

English · Русский · 中文

prt is a keyboard-driven terminal UI for inspecting network connections, finding port conflicts, exploring process details, and managing SSH tunnels on macOS and Linux. It combines a live connection table with filtering, change tracking, process topology, alerts, and script-friendly output.

Demo

Animated prt demo moving from live connections to process details, network topology, the command palette, and contextual actions

The 13-second demo plays directly in the README. You can also view a static frame or read the demo transcript. The recording is reproducible from docs/demo.tape.

Quick start

Requirements

  • Rust 1.75 or newer for installation with Cargo
  • macOS 10.15 or newer with the built-in lsof
  • Linux with a mounted /proc filesystem
  • A UTF-8 terminal; a wider window gives the table more room

Install and run

cargo install prt
prt

Run sudo prt when the operating system hides processes owned by other users. Elevated privileges are not required for normal use.

To build the current source instead:

git clone https://github.com/rekurt/prt.git
cd prt
cargo install --path crates/prt

What you can do

TaskHow prt helps
Find a port conflictSearch by port, process, protocol, state, service, PID, or user
Follow connection changesRefresh every two seconds; new and closed entries are highlighted
Investigate a processInspect command line, parent tree, CPU, memory, open files, and related connections
Review network topologySee process → local port → remote endpoint as a terminal tree
Spot suspicious listenersFilter entries flagged with [!] by the built-in heuristics
Work with containersShow the owning Docker or Podman container when one is detected
Manage SSH forwardingRead hosts from SSH config and create, restart, edit, or save tunnels
Automate checksExport one snapshot as JSON/CSV or stream NDJSON continuously

prt also estimates system-wide bandwidth, maps common ports to service names, supports configurable alerts, and offers contextual actions for process termination, firewall blocking, copying, tracing, and SSH forwarding.

Command-line modes

prt # launch the interactive TUI
prt --lang ru # start in Russian (en, ru, or zh)
prt --export json # print one JSON snapshot and exit
prt --export csv # print one CSV snapshot and exit
prt --json # continuously stream NDJSON
prt watch 80 443 5432 # compact UP/DOWN monitor for selected ports
sudo prt # include processes hidden from the current user

Use --export for a finite snapshot. --json keeps running and emits one object per connection on each scan cycle; it stops cleanly when a downstream command such as head closes the pipe.

Examples:

# Save a snapshot for comparison or incident notes.
prt --export json > ports.json
# Show process names from the live stream.
prt --json | jq -r '.process.name'# Watch only development ports.
prt watch 3000 5432 8080

Interface guide

Tab and Shift+Tab move between three top-level sections:

SectionPurposeSub-tabs
ConnectionsSortable connection table and optional details panelNone
ProcessesDetails for the selected process and its network topologyDetail, Topology
SSHHosts loaded from SSH config and managed tunnelsHosts, Tunnels

Press ? at any time for the in-app cheat sheet. Press : to search the command palette when remembering a shortcut is inconvenient.

Keyboard reference

KeyAction
?Open the help screen; any key closes it
qQuit
Tab / Shift+TabNext / previous section
SpaceOpen the contextual action menu
:Open the searchable command palette
/Search and filter; press Esc twice to clear a non-empty filter
pPause or resume automatic refresh
rRefresh now
sEnter a sudo password when more process visibility is needed
LCycle the interface language
j / k, / Move or scroll
g / G, Home / EndJump to the beginning or end
K / DeleteAsk to terminate the selected process
cCopy the selected connection

Section-specific keys:

ContextKeyAction
ConnectionsEnterOpen the selected process in the Processes section
ConnectionsdShow or hide the bottom details panel
Connectionso / OChoose the next sort column / reverse sort direction
Processes[ / ]Switch between Detail and Topology
SSH[ / ]Switch between Hosts and Tunnels
SSH HostsEnterStart a tunnel form for the selected host
SSH HostsrReload SSH and prt configuration
SSH Tunnelsn / eCreate / edit a tunnel
SSH TunnelsK / r / sKill / restart / save tunnels

Search and change tracking

Type / to filter the live table. Plain text matches visible connection data; status aliases such as new, gone, and active can narrow the lifecycle state. Type ! or suspicious to show entries flagged by the suspicious-connection detector.

New entries are green. Closed entries are dimmed red and remain visible for five seconds. Connection state and age remain available as text, but the new/gone distinction is currently color-based.

Configuration

The optional configuration file is ~/.config/prt/config.toml. A missing file uses defaults; a parse error is reported and defaults are used.

# Add or override service names.
[known_ports]
3000 = "frontend"5432 = "postgres"# Ring the terminal bell for a new SSH connection.
[[alerts]]
port = 22action = "bell"# Highlight Python listeners.
[[alerts]]
process = "python"state = "LISTEN"action = "highlight"# Add a host alongside entries from ~/.ssh/config.
[[ssh_hosts]]
alias = "staging"hostname = "staging.example.com"user = "deploy"port = 22

Alert conditions are port, process, state, and connections_gt. Actions are bell and highlight. Bell alerts fire only for new entries.

The SSH section also reads ~/.ssh/config. Saved tunnels are written back to the [[ssh_tunnels]] section of the prt config by the Tunnels view.

Safety and permissions

Scanning and navigation are read-only. Actions that change system state are grouped in the Space menu:

  • Process termination asks you to choose SIGTERM or SIGKILL.
  • Firewall blocking shows a confirmation and requires suitable privileges.
  • System-call tracing requires ptrace permissions on Linux or suitable dtruss permissions on macOS.
  • SSH forwarding starts an ssh subprocess using the values shown in the tunnel form.

Review the confirmation or form before proceeding. See the security policy for vulnerability reporting and the supported release policy.

Documentation accessibility

  • The README begins with a copyable quick start and uses descriptive link text.
  • The demo has a non-animated preview, descriptive alternative text, and a text transcript.
  • The TUI is fully keyboard-driven and includes an in-app help screen and command palette.
  • English, Russian, and Chinese interfaces and READMEs are available.
  • Connection states and suspicious entries have text labels; new/gone lifecycle cues are currently color-based.
  • Non-interactive JSON, CSV, NDJSON, and watch modes provide alternatives to the full-screen TUI.

If the terminal interface itself is not usable with your assistive technology, prt --export json is the most predictable machine-readable alternative.

Architecture

The repository is a Rust workspace with two crates:

crates/
├── prt-core/ scanning, tracking, filtering, alerts, configuration,
│ process details, containers, i18n, and platform adapters
└── prt/ clap CLI, ratatui interface, input handling, streaming,
watch mode, tracing, and SSH tunnel management

The main refresh flow is:

platform scan
→ Session refresh
→ diff New / Unchanged / Gone entries
→ enrich services, suspicious flags, and containers
→ retain recently closed entries
→ sample bandwidth and sort
→ evaluate alerts, filter, and render

macOS scans structured lsof output and batches process metadata lookups. Linux reads /proc/net through the procfs crate.

Library users can read the prt-core API documentation. Contributors should start with CONTRIBUTING.md.

Development

cargo build --workspace
cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings
cargo fmt --all -- --check

License

Licensed under the MIT License.

If prt is useful to you, consider starring the project on GitHub.

About

Real-time terminal UI for monitoring network ports — interactive alternative to lsof, ss, netstat with TUI, alerts, firewall, strace, containers and process trees

Topics

Resources

Contributing

Security policy

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages