> tools for the
terminal.
Zero-config diagnostics for the machines you run — network, system, disk, audio, SSH. Real-time, local-first, MIT-licensed.
Inspect connections, capture packets and investigate network problems. Available on Linux, macOS and Windows; capture access and diagnostic coverage vary by platform.
brew install netwatchTwelve tabs covering CPU, memory, disks, processes, GPU, power, services, and network — plus a Timeline scrubber and an Insights anomaly engine. The terminal you open when something feels off, before you reach for htop, iostat, nettop, and a notebook of one-liners. Sibling to netwatch.
brew install syswatchEight tabs across devices, volumes, filesystems, IO, SMART, hot files, and insights — capacity trends, throughput, p99 latency, and the files being written right now. Read-only, no daemon. Sibling to netwatch and syswatch.
brew install diskwatchInvestigate CPU contention, scheduling delays, memory pressure and block I/O with host counters and optional bounded eBPF tracing.
cargo install kernwatch --lockedTen tabs across devices, streams, meters, a real-time spectrum analyser, latency, xruns, and routing — for the one question no other terminal tool answers: why does my audio sound wrong? macOS and Linux, read-only by construction. Fourth sibling to netwatch.
git clone https://github.com/matthart1983/soundwatch && cd soundwatch && make installAn SSH workspace using OpenSSH and tmux. Reconnect to remote shells and inspect host health without leaving your terminal.
git clone https://github.com/matthart1983/essh.git && cd essh && cargo install --path . --lockedComplete Linux learning pathways and interactive teaching decks — systems, eBPF, networking, kernel contribution, Rust and the sequencer architecture. Explore mechanisms in your browser, then run guided C and Rust labs.
Linux systems training
Two complete pathways, from systems foundations to advanced kernel concepts. Each lesson includes guided experiments, worked explanations and checkpoints, with a downloadable C and Rust lab kit.
Twelve complete lessons with guided experiments, worked explanations, checkpoints and an engineering capstone. Includes a C and Rust lab kit, local progress tracking and an exportable notebook.
$ open linux-systems#advanced — start pathway →Eight guided lessons connect processes, descriptors, memory, concurrency, networking and persistence. Run the supplied experiments, check your reasoning and finish with a reproducible systems investigation.
$ open linux-systems#intro — start pathway →Builds eBPF from first principles up to NetWatch’s real aya kprobe — the VM, the verifier, maps and ring buffers, CO-RE — with drive-able simulations of the verifier, the issue-#38 timing bug, and the full connect()-to-process-name trace.
$ open ebpf-deep-dive — launch deck →A contributor walkthrough of the running system: the event loop, the DPI and TLS/QUIC decryption pipeline, eBPF attribution, the Landlock sandbox, the flight recorder, and the remote-publishing seam to the cloud.
$ open architecture-tour — launch deck →Follows a packet through every layer of the kernel: NIC/IRQ/NAPI, the sk_buff and struct sock, the RX and TX paths, netfilter’s five hooks, qdiscs, and the eBPF tap points. Drive the sk_buff pointers, step the TCP state machine, traverse the hooks.
$ open linux-network-stack — launch deck →The machinery of upstream kernel work: maintainer trees, the release cycle, the email-patch workflow, and surviving review. Explore the tree topology, scrub a release cycle, decode a patch email, and run the review gauntlet.
$ open linux-kernel-dev — launch deck →Rust’s hard part, made legible: ownership, borrowing, lifetimes, traits, errors, and fearless concurrency. Drive the borrow checker, scrub a lifetime, and watch a move invalidate a value — grounded in real NetWatch code.
$ open learning-rust — launch deck →The pattern behind Island/INET, Nasdaq, and LMAX, taught by driving it: stamp a command through the sequencer, crash and replay a node, reproduce a seeded VOPR fuzz run, drop packets on the A/B feeds, and kill a leader mid-stream — the machinery of ticktape, in Rust.
$ open ticktape-sequencer — launch deck →Same agent, hosted dashboard.
Run the same 5 MB Rust agent. Get fleet-wide metrics, alerts, and 72-hour history without standing up your own backend.