-
Notifications
You must be signed in to change notification settings - Fork 1
dashboard
Summary: The [o] view tiles seven bands vertically into one terminal. Bands grow proportionally with available rows; minimum recommended terminal is 100×33.
Sources: docs/views/dashboard.md, docs/views/top_hosts.md (embedded in dashboard.md), CLAUDE.md.
Last updated: 2026-05-25.
header (2 rows)
Interfaces band (height = iface_count)
Connections + Top hosts (= 2H, split 60/40)
Packets (= 2H)
WiFi APs | Summary | Beacons (H)
mDNS | DHCP | SSDP (H)
ARP | Deauth | Roaming clients (H)
DNS log | ICMP log (H, 50/50)
Bands sum to LINES exactly — spare rows from the integer divide go to conn / packets so the bottom band always reaches the last line.
Built by src/top_hosts.c:
- Aggregate
s->conns+s->conn_bwby remote IP each poll. - Skip RFC1918 / loopback / link-local / multicast / IPv6 link-local (this panel is about external traffic).
- Hostname follows the
[n]names/numeric toggle (#84 slice 2): with names on it goes through the async resolverdns_resolve(), which is itself strict-by-default and only reaches the network under--allow-active; with names off it reads the passivedns_lookup_cached(), which returns only what sloth already observed. The panel used to resolve on every poll regardless of the toggle, so numeric display still generated reverse-DNS egress. Owner comes from the embedded CDN / cloud prefix table insrc/ip_owner.c. -
first_seenis sticky across polls — the age column shows how long this destination has been around. - Sort by
rx_rate + tx_rate + conn_count, snapshot top 32.
Enhanced version of [7] Probe — same data source
(s->probe_clients[]), more columns: MAC, vendor (via oui_lookup(),
or (random) when locally-administered bit is set), last-probed SSID,
signal in dBm (coloured by strength), and a rough distance estimate
via the log-distance path-loss model. Treat distance as
order-of-magnitude only.
- IPs use the 8-colour hash palette — same IP, same colour everywhere. See ip-palette.
- An IP appearing in ≥ 2 panels renders bold. Instant cross-reference cue: a bold IP in packets that's also bold in conns and ARP wants your attention.
- Sparklines are heat-graded (cool → peak red).
_= zero sample.
- Bold IP in the packet stream that's also bold in conns and ARP.
- Sudden solid amber/red sparkline on a previously quiet flow.
- Top-hosts entry in a brand colour you weren't visiting.
- Any visible CRIT in the alerts panel.
- ip-palette — colour conventions used across every panel.
- views-catalog — links to each band's standalone view.
- alerts — the alert summary in the bottom-right.
Mirrored from docs/wiki/ on main by .github/scripts/wiki_sync.sh. Edit there, not here — hand edits to this wiki are overwritten on the next push.
Read this first — the complete reference
- what-sloth-does
- how-wifi-works
- monitor-mode
- where-exploits-happen
- wifi-sigint-techniques
- cli-reference
- wifi-state-of-the-art
Start here
Engines
WiFi SIGINT
- wifi-sigint
- non-ip-sensors
- mac-randomisation
- evil-twin-reproducer
- btm-abuse
- action-frames
- research-corpus
- captive-portal
- fragattacks
- tool-fingerprints
- enterprise-rogue
- ipv6-ndp
- smb-snoop
- kerberos-snoop
- ldap-snoop
- bgp-snoop
- ssh-snoop
- rdp-snoop
- snmp-snoop
- mqtt-snoop
UI and infrastructure
- ip-palette
- platform-vtable
- version-checkin
- manifest-format
- pcap-export
- jsonl-schema
- data-socket-exposure
- sqlite-schema
- ring-buffers
Factory infrastructure
Reference
Source material
Maintenance