Networking
Network Lens
Run one read-only Bash script on a Linux host and drop the JSON it produces here. Network Lens turns it into a picture: how the machine reaches the internet, what it is listening on, who it is talking to, and what the collector could not see. The report is read in this tab and never uploaded.
1 · Collect on the machine
The collector is read-only. It runs the operating system's own commands, writes one JSON file, makes no network requests and changes nothing. Read it before you run it — that is why it ships as a file rather than something you pipe into a shell.
Uses iproute2 (ip, ss) and /proc. macOS is not supported — the BSD userland is different enough that shipping it untested would be worse than not shipping it.
Download and read it
curl -fsSLO https://surajkr.dev/netlens.sh && less netlens.sh Check it is the file I published — netlens.sh, 596 lines
echo "df8e795a73b66485259338927fa2fe72af391e2748f1aad58ca98bbefd82bf03 netlens.sh" | sha256sum -c
Run it — add --redact if you intend
to share the report
bash netlens.sh Run with sudo to include firewall and NAT rules. Without that it still works and tells you what it could not see.
Uses the NetTCPIP cmdlets (Get-NetTCPConnection, Get-NetRoute, Get-NetNeighbor).
Download and read it
iwr https://surajkr.dev/netlens.ps1 -OutFile netlens.ps1; notepad netlens.ps1 Check it is the file I published — netlens.ps1, 438 lines
(Get-FileHash .\netlens.ps1 -Algorithm SHA256).Hash -eq "1DB4E5EE1C8B5E05D358E09BEB6E6EE38B2E6487E3A29E650EFD1AD1EE6994BD"
Run it — add -Redact if you intend
to share the report
powershell -ExecutionPolicy Bypass -File .\netlens.ps1 Run as Administrator to include firewall and NAT rules. Without that it still works and tells you what it could not see.
2 · Open the report here
or paste it
The machine
How this machine connects
Built from the default route, the interface carrying it, what is listening, and the connections that were actually open when the report ran.
Who could reach this machine
Listening sockets grouped by what they are bound to. A local snapshot cannot prove what a firewall elsewhere allows, so this is exposure as the host sees it — not a reachability test.
What this machine can reach
A route existing is not proof of reachability. Anything marked observed had a live connection or a resolved neighbour at collection time; everything else is only what the routing table claims.
| Destination | Via | Device | Evidence |
|---|
Open connections
| Process | Local | Peer | Port | Scope |
|---|
Interfaces and neighbours
| Interface | State | Addresses | MTU |
|---|
| Neighbour | Device | State |
|---|
Observations
Things worth a second look — not vulnerabilities. Whether any of them is a problem depends on what this machine is for, which the report cannot know.
What the collector could see
An incomplete report that looks complete is the dangerous kind, so this is stated plainly.
What this is and is not
- It correlates evidence the machine already has. Linux knows its interfaces, routes, neighbours, sockets and sessions. Nothing here is discovered by probing the network — no scan is performed, and no packet is sent.
- It cannot prove external reachability. A listener bound to
0.0.0.0is reachable from any network this host sits on, but a security group, a cloud ACL or an upstream firewall may still block it. That evidence is not on this machine. - Without root it sees less. Firewall rules, NAT counters and the process behind a socket owned by another user all need privilege. The report records what it missed rather than quietly omitting it.
- Treat the report as sensitive. It contains internal addressing, hostnames,
listening services and the source addresses of live sessions. Use
--redactbefore putting one in a ticket.
Runs entirely in your browser — nothing you type here is uploaded, logged or stored. Privacy policy