Automic VaultAutomic Vault

brew

Install netwatch with Homebrew, Nix, pacman, scoop

Cross-platform realtime network diagnostics TUI. Version 0.26.1 via Homebrew; verified 2026-07-04. Also installable with nix: nix profile install nixpkgs#netwatch.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install netwatch

local Homebrew formula metadata

Linux

Nixverified · 92%
nix profile install nixpkgs#netwatch

nixpkgs package indexes · pkgs/by-name/ne/netwatch/package.nix · source: api.github.com

Arch Linux pacmanverified · 92%
sudo pacman -S netwatch

Arch Linux sync databases · netwatch · source: geo.mirror.pkgbuild.com

Windows

Scoopverified · 92%
scoop install main/netwatch

Scoop official bucket manifest trees · bucket/netwatch.json · source: api.github.com

overview

Package summary

Cross-platform realtime network diagnostics TUI

Commands and aliases

  • netwatch

history

Project history and usage

NetWatch is a young Rust terminal tool for live network diagnostics and forensics. Its upstream README positions it as a zero-config binary for seeing live network activity, mapping connections to processes, decoding protocols, and preserving incident evidence from a terminal workflow.

Project history

The public project is centered on matthart1983/netwatch and the NetWatch Labs site. GitHub showed the repository at roughly 2.2k stars, 84 forks, 282 commits, and 60 releases when researched on 2026-07-01. Homebrew listed stable version 0.25.9, matching the active cadence visible in the GitHub releases page.

Adoption history

Adoption looks like a fast-moving specialist tool rather than a long-established Unix utility. Homebrew analytics reported 275 install-on-request events over 30, 90, and 365 day windows, which suggests Homebrew adoption was concentrated in a single early window. The upstream README also exposes crates.io and release badges and mentions Terminal Trove recognition, so its early spread appears to be through Rust/terminal-tool circles and security/networking communities.

How it is used

Package users install it as a single binary and run `netwatch` for interface stats, connection views, and configuration, or `sudo netwatch` for packet capture and health probes. The README documents a TLS inspection workflow using `SSLKEYLOGFILE` for traffic the operator controls, plus tabs for dashboard, connections, interfaces, packets, stats, topology, timeline, processes, and optional insights.

The package-nerd angle is that NetWatch bundles several tasks people often split across `iftop`, `lsof`, `ss`, `tcpdump`, Wireshark, and ad hoc shell pipelines: per-process network attribution, libpcap capture, protocol decoding, TLS keylog-file decryption, JA4-oriented threat hunting, and evidence bundle export.

Why package nerds care

NetWatch is notable less as a foundational package and more as part of the 2025-2026 wave of Rust TUI observability tools: one static-ish terminal binary with polished UX, Homebrew packaging, Cargo install path, and security-oriented defaults.

Timeline

  • 2026-06-27: GitHub releases page showed v0.25.9.
  • 2026-07-01: Homebrew formula API reported stable 0.25.9 and 275 install-on-request events in the 365-day analytics window.

Related projects

  • SysWatch and DiskWatch are listed by upstream as sibling tools with the same TUI style.
  • NetWatch Cloud, netwatch-agent, netwatch-sdk, and netwatch-dashboard are related projects referenced from the upstream README.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for netwatch. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Build metadata lists 1 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
netwatchcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-07-25
manager version0.26.1
manager updated2026-07-04
local dataok
upstreamcurrent
latest detectedv0.26.1

https://github.com/matthart1983/netwatch

  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:netwatch
Version0.26.1
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/netwatch
Homepagehttps://www.netwatchlabs.com/labs/netwatch
Repositoryhttps://github.com/matthart1983/netwatch
Upstream docshttps://github.com/matthart1983/netwatch#readme
LicenseMIT
Source archivehttps://github.com/matthart1983/netwatch/archive/refs/tags/v0.26.1.tar.gz
Last updated2026-07-04T07:03:38Z
Pulseupdated
Build dependenciesrust
Uses from macOSlibpcap
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namenetwatch
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

netwatch

nix profile install nixpkgs#netwatch
  • normalized package name match
  • Matched by: Netwatch
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ne/netwatch/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

netwatch 1.3.1_2-4

monitor network connections

http://www.slctech.org/~mackay/NETWATCH/netwatch.html

sudo pacman -S netwatch
  • License: GPL
  • Architecture: x86_64
  • 1 dependencies
  • normalized package name match
  • Matched by: Netwatch
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: netwatch from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
Scoop95%

main/netwatch

scoop install main/netwatch
  • normalized package name match
  • Matched by: Netwatch
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/netwatch.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment