What Snitchy Witch Actually Is

Snitchy Witch is a macOS application designed to monitor and alert you about network activity, specifically processes that perform network sniffing or packet capture on your system. It runs in the background, watches for tools like tcpdump, Wireshark, or any process attempting to put a network interface into promiscuous mode, and notifies you when something is detected. If you've ever had to verify whether someone on your local network was capturing traffic, this tool was built for that scenario. The app hooks into system-level network events and keeps a log of every process that attempts packet capture. It displays these in a clean menu bar interface so you can see what's happening at a glance. Installation is straightforward — download the DMG from the developer's site, drag it to Applications, and run it. You'll likely need to grant accessibility permissions during setup, which is standard for tools that monitor system-level events on macOS. I ran into an issue a while back where Snitchy Witch was generating false positives from legitimate development tools. Specifically, a Go-based network testing utility I was using for work would trigger alerts because it intentionally put interfaces into promiscuous mode for benchmarking. The fix was adding an exclusion list entry for that specific binary path in the app's settings. The developer documents this in the readme, but it's not immediately obvious unless you've hit the problem yourself. Once I configured the exclusions properly, the noise dropped significantly and the remaining alerts were accurate.

Limitations and What It Won't Do

Snitchy Witch is fairly narrow in scope. It detects active packet capture attempts but does not provide deep packet inspection or payload decryption. If someone is already running a sophisticated capture tool with root-level access, the alerts may appear but you won't be able to see what they captured through this tool alone. It's a detection layer, not a prevention layer. That distinction matters. Another practical limitation is that it only monitors processes spawned after the app is running. If someone boots your machine with a preconfigured script that starts sniffing immediately, Snitchy Witch will log it but you might miss the initial event depending on when you launched the app. Running it at login helps mitigate this, but it's not foolproof against targeted attacks that execute before user-space tools are fully initialized. The developer's site hosts the latest version. Check the releases page for macOS compatibility notes, especially if you're running a newer macOS version since kernel extensions and system integrity changes have affected similar tools in the past.

Who Should Use This

If you're managing a shared Mac environment or working in a space where network monitoring by unauthorized processes is a concern, Snitchy Witch is a lightweight option. It's not going to replace a full SIEM or network detection platform, but for individual users and small teams who want a simple indicator of whether someone or something is sniffing traffic on their machine, it does the job without consuming much resources. Pair it with standard network monitoring practices and you get a reasonable baseline without overcomplicating things.

Get the Full Details

Snitchy Witch! 🧙🧹READ TO ME - YouTube
Snitchy Witch! 🧙🧹READ TO ME - YouTube