Skip to content
aiXis Studio edited this page Oct 4, 2026 · 1 revision

FAQ / Questions fréquentes

🇬🇧 English

Is Snitch a firewall like Little Snitch? No — Little Snitch blocks connections; Snitch visualizes and explains them. They're complementary. Snitch is also free, open-source (AGPL-3.0), cross-platform and makes zero outbound calls.

Does it need root/admin? Live capture: yes — that's how libpcap/BPF works (same as Wireshark). On Linux you can grant cap_net_raw to avoid running as root permanently. Demo mode (SNITCH_DEMO=1) needs no privileges at all.

Does any data leave my machine? No. SQLite + logs stay local; the API binds 127.0.0.1 behind a per-launch token. The single possible outbound request is the opt-in DB-IP Lite download in Settings — and even geolocation works offline without it.

How accurate is process attribution? Best-effort: Snitch snapshots OS connections via psutil and maps (proto, local_port) → (pid, name) — top 5 per connection. It can't attribute short-lived sockets that closed between snapshots.

Why is the macOS build unsigned? No Apple Developer certificate in the project budget. Right-click → Open works fine, and the whole pipeline is reproducible from source if you prefer building it yourself.

Windows/Linux native installers? Linux: use Docker (sudo docker compose up --build). Windows: build from source (Npcap required). Native installers are on the Roadmap.

What languages does the UI support? English and French — full interface, alerts and settings, one-click EN / FR toggle.

Does it slow down my machine? The pipeline is deliberately low-overhead: one bounded queue, one drain task at ~4 Hz, batched WebSocket updates every 250 ms. No per-packet coroutines.

Can I extend the tracker lists? Yes — backend/classifier/lists/ holds plain-text domain lists. Add domains, restart the backend.

Why not just use Wireshark? Wireshark dissects raw packets for experts. Snitch gives the live, high-level "who talks to whom" picture anyone can read — graph, map, per-app, alerts.

🇫🇷 Français

Snitch est-il un pare-feu comme Little Snitch ? Non — Little Snitch bloque les connexions ; Snitch les visualise et les explique. Les deux sont complémentaires. Snitch est en plus gratuit, open-source (AGPL-3.0), multiplateforme et n'émet aucun appel sortant.

Faut-il les droits root/admin ? Pour la capture réelle : oui — c'est le fonctionnement de libpcap/BPF (comme Wireshark). Sous Linux, cap_net_raw permet d'éviter le root permanent. Le mode démo (SNITCH_DEMO=1) n'exige aucun privilège.

Des données quittent-elles ma machine ? Non. SQLite + logs restent locaux ; l'API écoute sur 127.0.0.1 derrière un jeton par lancement. Le seul appel sortant possible est le téléchargement opt-in de DB-IP Lite dans Réglages — et la géolocalisation fonctionne déjà hors ligne sans lui.

L'attribution par processus est-elle fiable ? Best-effort : Snitch prend des instantanés psutil et associe (proto, port_local) → (pid, nom) — top 5 par connexion. Les sockets éphémères fermées entre deux instantanés ne peuvent pas être attribuées.

Pourquoi la build macOS n'est-elle pas signée ? Pas de certificat Apple Developer dans le budget du projet. Clic droit → Ouvrir fonctionne, et toute la chaîne est reproductible depuis les sources si vous préférez la compiler vous-même.

Des installateurs natifs Windows/Linux ? Linux : utilisez Docker (sudo docker compose up --build). Windows : compilation depuis les sources (Npcap requis). Les installateurs natifs sont sur la feuille de route.

Quelles langues pour l'interface ? Français et anglais — interface complète, alertes et réglages, bascule EN / FR en un clic.

Peut-on étendre les listes de trackers ? Oui — backend/classifier/lists/ contient des listes de domaines en texte brut. Ajoutez vos domaines, redémarrez le backend.

Pourquoi pas simplement Wireshark ? Wireshark dissèque des paquets bruts pour experts. Snitch donne la vue d'ensemble en direct « qui parle à qui » lisible par tous — graphe, carte, vue par app, alertes.

Snitch Wiki

Getting started / Démarrage

  • Installation — EN · FR
  • Usage / Utilisation — EN · FR

Docs (EN + FR)

Help / Aide (EN + FR)

Project / Projet

Clone this wiki locally