A self-hosted network monitor & bandwidth-control tool for Linux. Discover every device on your WiFi, identify them, watch live bandwidth, see which sites they open, throttle or fully cut anyone's internet, prioritise your own devices, and even switch WiFi networks β all from a polished, real-time web dashboard you can open from your phone.
π΄ Live Demo Β· runs on simulated data β no install needed
β οΈ About this repository. This is the public showcase: the complete frontend (Vue 3 + Vite + Tailwind) running in demo mode with simulated data, so anyone can click the live link and explore the full UI/UX. The privileged backend that does the real network work (raw-socket scanning, ARP interception,tctraffic shaping,netfilter, packet inspection) is kept in a private repository.
| π Device discovery | Auto ARP/mDNS/DHCP scan, vendor + OS + model fingerprinting (e.g. iPhone 13 Pro, Galaxy S23, Windows laptop) |
| π·οΈ Smart naming | Reverse-DNS + NetBIOS + mDNS + DHCP hostname sniffing (NetCut-style) β even names randomized-MAC phones |
| π Live bandwidth | Real-time per-device download/upload with animated bars + "top consumers" ranking |
| π Activity insight | Which services a device is opening (Instagram, YouTube, TikTokβ¦) via DNS + TLS-SNI β noise filtered to friendly names |
| π΄ Throttle | Cap any device's speed without touching the router |
| β Cut internet | Drop a device's internet while it stays connected to WiFi (not a deauth) |
| π Lockdown mode | One switch: only your whitelisted devices keep internet β auto-applies to new joiners |
| π Boost / priority | Squeeze everyone else so your own device gets the bandwidth |
| π‘οΈ Whitelist | Pin your devices β never throttled, never cut, always prioritised |
| πΆ WiFi switcher | Scan nearby networks, connect with a password, the whole tool follows you |
| β‘ Speed test | Built-in before/after speed tests to prove the effect of boost |
| π Telegram alerts | Get pinged when a new device joins |
| π Optional auth | Password-gate the dashboard for remote access |
Multi-page SPA: Dashboard Β· Monitor Β· WiFi Β· Speed Test β with smooth transitions, skeleton loaders, toasts and live SSE updates.
| Monitor β live bandwidth & opened sites | WiFi β scan & switch networks |
|---|---|
| Speed Test β prove the boost |
|---|
Frontend β Vue 3 (<script setup>), Vite, Tailwind CSS v4, composable state
store, Server-Sent Events for realtime, zero heavy deps.
Backend (private) β Python + Flask, raw AF_PACKET sockets, arp-scan /
nmap, arpspoof, Linux tc HTB, iptables/nftables, conntrack, nmcli,
mDNS, and a hand-written DHCP/DNS/TLS-SNI packet parser.
Phone / Tablet / any device on the LAN
β browser
βΌ
ββββββββββββββββββββββββββββββββββ
β Vue 3 SPA (this repo) β Dashboard Β· Monitor Β· WiFi Β· SpeedTest
βββββββββββββββββ¬βββββββββββββββββ
β JSON + SSE (realtime)
βΌ
ββββββββββββββββββββββββββββββββββ
β Flask API (private) β /api/devices /throttle /block /boost β¦
βββββββββββββββββ¬βββββββββββββββββ
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββ
β Linux host (root) β
β β’ discovery: arp-scan + ARP cache + mDNS β
β β’ naming: reverse-DNS + NetBIOS + DHCP sniff β
β β’ bandwidth: conntrack accounting β
β β’ control: arpspoof + tc HTB + iptables β
β β’ traffic: raw-socket DNS / TLS-SNI parser β
β β’ wifi: nmcli scan / connect β
ββββββββββββββββββββββββββββββββββββββββββββββββ
- Discovery & naming. Combines active ARP scanning with the kernel ARP cache, then enriches each device from the OUI vendor database, mDNS broadcasts, and DHCP Option-12 hostnames sniffed off a raw socket β the trick that reveals names of modern phones that otherwise hide behind randomized MACs.
- Per-device bandwidth. Other devices' traffic doesn't normally pass through
your laptop, so a device is briefly ARP-spoofed to route through the host,
where
conntrackbyte-accounting measures it live. - Throttle / cut. Traffic is shaped with a Linux
tcHTB class per device, or dropped with anetfilterFORWARD rule β the device stays associated to the AP but loses internet, no deauth. - Activity. A hand-written parser reads DNS queries and TLS ClientHello SNI off the wire to show which services are being opened (domains only β HTTPS payloads stay encrypted), then collapses noisy CDN/tracker domains into recognisable names.
npm install
npm run build:demo # simulated-data build
npm run preview # serves the static demo
# or: npm run dev # hot-reload dev serverDeploying the live demo to Cloudflare Pages / Vercel: see DEPLOY.md.
Built for monitoring and managing your own home WiFi β parental controls, catching freeloaders, prioritising your work device. ARP-based control on a network you don't own is illegal in many places; use the passive/identification features only on networks that aren't yours.
MIT Β© Bintang Samudra β see LICENSE.