Little Snitch for Linux — eBPF Network Monitor
Skill by ara.so — Daily 2026 Skills collection.
Little Snitch for Linux is an open-source eBPF-based network monitoring and blocking toolkit written in Rust. It attaches eBPF programs to the Linux kernel to intercept network connections, then shares data between kernel and user space via eBPF maps. The open-source portion includes eBPF programs, shared types, and a demo runner; the full product from Objective Development includes additional proprietary UI and rule-engine components.
Architecture Overview
Crates:
ebpf/— eBPF kernel-space programs (compiled to BPF bytecode)common/— Shared types between kernel and user spacedemo-runner/— User-space loader and event consumerwebroot/— JavaScript web UI
Prerequisites
Rust Toolchains
System Dependencies
Kernel Requirements
- Linux kernel 5.15+ (for BTF and CO-RE support)
- eBPF enabled in kernel config (
CONFIG_BPF=y,CONFIG_BPF_SYSCALL=y) CAP_BPFor root privileges to load eBPF programs
Build & Run
Note: Cargo build scripts automatically compile the eBPF programs and embed them in the binary — no manual eBPF compilation step needed.
Blocklist Configuration
The demo runner loads two blocklist files at startup:
blocked_hosts.txt
One IP address or hostname per line:
blocked_domains.txt
One domain suffix per line (blocks domain and all subdomains):
Place these files in the working directory before running:
Common Crate — Shared Types
The common crate defines types shared between kernel eBPF code and user-space. When extending the project, add new shared types here.
eBPF Crate — Kernel Programs
eBPF programs live in ebpf/src/ and are compiled to BPF bytecode using the nightly toolchain.
Demo Runner — User Space Loader
The demo runner uses Aya to load eBPF programs and interact with maps.
Adding a New Blocked Domain
Reading Events from Kernel
Cargo.toml Structure
Troubleshooting
"Operation not permitted" when loading eBPF
Build fails: bpf-linker not found
eBPF verifier rejects program
- Reduce map sizes or loop bounds
- Ensure all memory accesses are bounds-checked
- Check kernel version supports the helpers you're using:
Map not found error
blocked_hosts.txt not found
License
All code in this repository is licensed under GPL-2.0. Contributions submitted to this project are licensed under the same terms.


