-
Notifications
You must be signed in to change notification settings - Fork 1
views catalog
Summary: Full keybinding-to-view map, with one-line descriptions and links to the per-view source docs in docs/views/.
Sources: view_labels[] in src/view_labels.c (the one table the
tab bar and the help card both render from), VIEW_COUNT in
include/sloth.h, docs/views/README.md and all docs/views/*.md.
Count: VIEW_COUNT = 35. Every key below is a row of
view_labels[]; if the two disagree, view_labels[] is right.
Last updated: 2026-09-23 (#96 — eight views were missing here).
| Key | View | Source doc | One-liner |
|---|---|---|---|
1 |
Interfaces | interfaces.md | rtnetlink + sysfs view of every iface |
2 |
Connections | connections.md | TCP/UDP sockets + PID + RTT + retx (INET_DIAG) |
3 |
WiFi | wifi.md | nl80211 stations, signal, link state |
4 |
Packets | packets.md | live pcap, BPF filter, hex detail, pcap export |
5 |
Processes | processes.md | per-process socket inventory |
6 |
Stats | stats.md | counters from /proc/net/snmp
|
7 |
Probe | probe.md | 802.11 probe-request sniffer |
8 |
ARP | arp.md | kernel ARP table |
9 |
mDNS | mdns.md | multicast DNS service announcements |
0 |
NBNS | nbns.md | NetBIOS name service / LLMNR |
d |
DHCP | dhcp.md | DHCP DISCOVER/OFFER/REQUEST/ACK |
s |
SSDP | ssdp.md | UPnP discovery |
b |
Beacons | beacons.md | passive 802.11 beacon sniffer |
a |
Deauth | deauth.md | deauth / disassoc + flood detection |
h |
HTTP | http.md | plaintext HTTP req log |
t |
TLS | tls.md | ClientHello, SNI, JA3 — see ja3-fingerprinting |
u |
QUIC | quic.md | QUIC initials |
r |
DNS | dns.md | every Q/R on UDP/53 |
p |
NTP | ntp.md | NTP traffic |
i |
ICMP | icmp.md | ICMP log |
m |
Channel | channel.md | per-channel 802.11 activity histogram |
| Key | View | Source doc | One-liner |
|---|---|---|---|
v |
Alerts | alerts.md | rule-derived events — see alerts |
g |
Devices | devices.md | join of ARP + DHCP + beacons + probes + stations |
o |
Dashboard | dashboard.md | seven-band composite — see dashboard |
l |
OSI stack | osi.md | every observed count mapped onto its OSI layer |
x |
Twins | twins.md | evil-twin episode table |
y |
KARMA | karma.md | KARMA / PineAP candidate table (#30) |
z |
RADIUS | rogue-radius.md | 802.1X EAP method / identity-leak table (#31, #38) — see enterprise-rogue |
c |
FragAttacks | fragattack.md | per-BSSID FragAttacks counters (#75) — see fragattacks |
f |
Research | research.md | the cited source behind each alert that fired (#73) — see research-corpus |
? |
Help | — | keybindings, version, and the embedded-data disclosures |
See wifi-sigint for the full SIGINT primitives.
| Key | View | Source doc | One-liner |
|---|---|---|---|
k |
PNL | pnl.md | per-MAC PNL aggregation + OS fingerprint |
e |
EAPOL | eapol.md | PMKID + 4-way handshake capture |
j |
Seqnum | seqnum.md | MAC-randomisation deanonymisation — see mac-randomisation |
w |
Assoc | assoc.md | confirmed STA ↔ AP associations |
See CLAUDE.md "How to add a new view" — 11-step checklist that keeps
VIEW_COUNT in sync, lays out the file, wires the key, and demands a
test + a per-view doc.
Mirrored from docs/wiki/ on main by .github/scripts/wiki_sync.sh. Edit there, not here — hand edits to this wiki are overwritten on the next push.
Read this first — the complete reference
- what-sloth-does
- how-wifi-works
- monitor-mode
- where-exploits-happen
- wifi-sigint-techniques
- cli-reference
- wifi-state-of-the-art
Start here
Engines
WiFi SIGINT
- wifi-sigint
- non-ip-sensors
- mac-randomisation
- evil-twin-reproducer
- btm-abuse
- action-frames
- research-corpus
- captive-portal
- fragattacks
- tool-fingerprints
- enterprise-rogue
- ipv6-ndp
- smb-snoop
- kerberos-snoop
- ldap-snoop
- bgp-snoop
- ssh-snoop
- rdp-snoop
- snmp-snoop
- mqtt-snoop
UI and infrastructure
- ip-palette
- platform-vtable
- version-checkin
- manifest-format
- pcap-export
- jsonl-schema
- data-socket-exposure
- sqlite-schema
- ring-buffers
Factory infrastructure
Reference
Source material
Maintenance