Skip to content

views catalog

sloth wiki-sync edited this page Sep 30, 2026 · 1 revision

Views catalog

Summary: Full keybinding-to-view map, with one-line descriptions and links to the per-view source docs in docs/views/.

Sources: view_labels[] in src/view_labels.c (the one table the tab bar and the help card both render from), VIEW_COUNT in include/sloth.h, docs/views/README.md and all docs/views/*.md.

Count: VIEW_COUNT = 35. Every key below is a row of view_labels[]; if the two disagree, view_labels[] is right.

Last updated: 2026-09-23 (#96 — eight views were missing here).


Observation — straight from the wire / kernel

Key View Source doc One-liner
1 Interfaces interfaces.md rtnetlink + sysfs view of every iface
2 Connections connections.md TCP/UDP sockets + PID + RTT + retx (INET_DIAG)
3 WiFi wifi.md nl80211 stations, signal, link state
4 Packets packets.md live pcap, BPF filter, hex detail, pcap export
5 Processes processes.md per-process socket inventory
6 Stats stats.md counters from /proc/net/snmp
7 Probe probe.md 802.11 probe-request sniffer
8 ARP arp.md kernel ARP table
9 mDNS mdns.md multicast DNS service announcements
0 NBNS nbns.md NetBIOS name service / LLMNR
d DHCP dhcp.md DHCP DISCOVER/OFFER/REQUEST/ACK
s SSDP ssdp.md UPnP discovery
b Beacons beacons.md passive 802.11 beacon sniffer
a Deauth deauth.md deauth / disassoc + flood detection
h HTTP http.md plaintext HTTP req log
t TLS tls.md ClientHello, SNI, JA3 — see ja3-fingerprinting
u QUIC quic.md QUIC initials
r DNS dns.md every Q/R on UDP/53
p NTP ntp.md NTP traffic
i ICMP icmp.md ICMP log
m Channel channel.md per-channel 802.11 activity histogram

Synthesis — derived from observation

Key View Source doc One-liner
v Alerts alerts.md rule-derived events — see alerts
g Devices devices.md join of ARP + DHCP + beacons + probes + stations
o Dashboard dashboard.md seven-band composite — see dashboard
l OSI stack osi.md every observed count mapped onto its OSI layer
x Twins twins.md evil-twin episode table
y KARMA karma.md KARMA / PineAP candidate table (#30)
z RADIUS rogue-radius.md 802.1X EAP method / identity-leak table (#31, #38) — see enterprise-rogue
c FragAttacks fragattack.md per-BSSID FragAttacks counters (#75) — see fragattacks
f Research research.md the cited source behind each alert that fired (#73) — see research-corpus
? Help — keybindings, version, and the embedded-data disclosures

WiFi SIGINT (v1.1)

See wifi-sigint for the full SIGINT primitives.

Key View Source doc One-liner
k PNL pnl.md per-MAC PNL aggregation + OS fingerprint
e EAPOL eapol.md PMKID + 4-way handshake capture
j Seqnum seqnum.md MAC-randomisation deanonymisation — see mac-randomisation
w Assoc assoc.md confirmed STA ↔ AP associations

Adding a view

See CLAUDE.md "How to add a new view" — 11-step checklist that keeps VIEW_COUNT in sync, lays out the file, wires the key, and demands a test + a per-view doc.

Related pages

Clone this wiki locally