sloth
A fully passive forensic tool. It never injects packets, scans, or touches kernel state. 23 live ncurses views: 802.11 beacon / probe / deauth sniffing, ARP / mDNS / NBNS / DHCP / SSDP device discovery, TLS ClientHello and JA3 fingerprint capture, and synthesized alerts for port scans, deauth floods, NXDOMAIN bursts, threat-intel hits, and periodic beaconing. JSONL log and per-alert pcap for downstream analysis.
- LanguageC99, from the kernel-facing code up
- Tests50 C unit tests plus a
fake_platformshim - PosturePassive only: observe, never emit
- OutputForensic JSONL + per-alert pcap
