Networking

Network Lens

Run one read-only Bash script on a Linux host and drop the JSON it produces here. Network Lens turns it into a picture: how the machine reaches the internet, what it is listening on, who it is talking to, and what the collector could not see. The report is read in this tab and never uploaded.

1 · Collect on the machine

The collector is read-only. It runs the operating system's own commands, writes one JSON file, makes no network requests and changes nothing. Read it before you run it — that is why it ships as a file rather than something you pipe into a shell.

Uses iproute2 (ip, ss) and /proc. macOS is not supported — the BSD userland is different enough that shipping it untested would be worse than not shipping it.

1

Download and read it

curl -fsSLO https://surajkr.dev/netlens.sh && less netlens.sh
2

Check it is the file I published — netlens.sh, 596 lines

echo "df8e795a73b66485259338927fa2fe72af391e2748f1aad58ca98bbefd82bf03 netlens.sh" | sha256sum -c
3

Run it — add --redact if you intend to share the report

bash netlens.sh

Run with sudo to include firewall and NAT rules. Without that it still works and tells you what it could not see.

2 · Open the report here

or paste it

What this is and is not

  • It correlates evidence the machine already has. Linux knows its interfaces, routes, neighbours, sockets and sessions. Nothing here is discovered by probing the network — no scan is performed, and no packet is sent.
  • It cannot prove external reachability. A listener bound to 0.0.0.0 is reachable from any network this host sits on, but a security group, a cloud ACL or an upstream firewall may still block it. That evidence is not on this machine.
  • Without root it sees less. Firewall rules, NAT counters and the process behind a socket owned by another user all need privilege. The report records what it missed rather than quietly omitting it.
  • Treat the report as sensitive. It contains internal addressing, hostnames, listening services and the source addresses of live sessions. Use --redact before putting one in a ticket.

Runs entirely in your browser — nothing you type here is uploaded, logged or stored. Privacy policy