Making the Invisible Internet Visible. A beginner-friendly, production-grade Internet observability platform built in Rust and React/Tauri.
NetPulse reconstructs, explains, and teaches the complete story behind network events on your computer β locally, privately, and beautifully. Instead of showing raw packet bytes first, NetPulse delivers understanding first, keeping deep technical inspection one click away.
- Observe, Don't Intervene: Listens passively. Never blocks, injects, or alters network traffic.
- Local-First & Private: Offline parsing, flow reconstruction, and anomaly detection. Single egress boundary in
netpulse-ai. - Calibrated Confidence: Every security finding carries an explicit confidence score linked to exact packet/flow evidence.
- Progressive Disclosure: One rich data model served across three customizable depth levels (Beginner, Intermediate, Expert).
NetPulse capabilities are specified, implemented, and executed across three distinct maturity dimensions:
- Design: Architecture, specs, contracts, and privacy bounds.
- Code: Parsers, data models, state machines, and unit tests.
- Runtime: Active execution in standard builds, live OS capture, persistent DB, or GUI integration.
Status Legend: β
Complete | π§ In Progress | π Planned | Single Source of Truth: docs/status.yml
| Capability | Key Crates & Packages | Design | Code | Runtime | Description |
|---|---|---|---|---|---|
| Capture & Decoding | netpulse-capture, netpulse-decode, netpulse-flow, netpulse-storage, netpulse-platform |
β Complete | β Complete | β Complete | Zero-copy decoding (Ethernet, IPv4/6, TCP, UDP, DNS, HTTP, TLS), flow assembly, hostile input bounds, PCAP/PCAPNG parsing & replay, live Npcap capture with interface fallback, and durable SQLite storage with restart hydration fully operational. |
| Narrative & Presentation | netpulse-narrative, netpulse-api, @netpulse/contract, @netpulse/components, @netpulse/viz, @netpulse/design-system |
β Complete | β Complete | β Complete | Session narrative card projection, v6 API DTO contract, real-time bandwidth/latency telemetry streaming, Windows process attribution (GetExtendedTcpTable), and progressive disclosure UI components fully operational. |
| Education & Exploration | netpulse-learn, @netpulse/app |
β Complete | β Complete | β Complete | Interactive curriculum engine, Website Load Journey synthesizer, Protocol Explorer reference content, persistent local mastery engine, and interactive lesson player UI fully operational. |
| Intelligence & AI | netpulse-intel, netpulse-ai |
β Complete | β Complete | π§ In Progress | Threat detectors (DNS tunneling, port scans), statistical anomaly engine, grounded retrieval & LocalTemplateBackend complete. Local ONNX LLM backend planned. |
| Lifecycle & Plugins | netpulse-engine, netpulse-plugin, netpulse-capture-svc |
β Complete | π§ In Progress | π§ In Progress | Deterministic replay controller, plugin seam traits, Ed25519 trust derivation, and durable write-behind persistence of the committed capture. Recording is not yet wired into the live capture loop and PCAPNG export needs captured frames, so both refuse with a reason instead of reporting a success that never happened. WASM runtime loader & privileged daemon loop in progress/planned. |
NetPulse separates responsibilities across distinct processes to maintain privilege isolation and system stability. The crate dependency graph strictly enforces a downward hierarchy. Higher layers depend on lower layers, never the reverse.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Desktop User UI β
β βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ β
β β Vite + React Application β β
β β (@netpulse/app, @netpulse/components, @netpulse/viz) β β
β βββββββββββββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββ β
β β IPC (Tauri v2 invoke / events) β
β βββββββββββββββββββββββββββββββββββΌββββββββββββββββββββββββββββββββββ β
β β Tauri Desktop Shell (`src-tauri`) β β
β βββββββββββββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββ β
ββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββ
β Query / Command (netpulse-api v4)
ββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββ
β Engine Process (`netpulse-engine`) β
β β
β ββββββββββββββββ ββββββββββββββββ ββββββββββββββββ ββββββββββββ β
β β narrative β β intel β β learn β β ai β β
β ββββββββ¬ββββββββ ββββββββ¬ββββββββ ββββββββ¬ββββββββ ββββββ¬ββββββ β
β ββββββββββββββββββββΌβββββββββββββββββββ β β
β βΌ β β
β ββββββββββββββββ ββββββββββββββββ ββββββββββββββββ β β
β β storage βββββ flow βββββ decode β β β
β ββββββββββββββββ ββββββββββββββββ ββββββββ¬ββββββββ β β
β β² β β β
ββββββββββββββββββββββββββββββΌβββββββββββββββββββΌβββββββββββββββββΌβββββββββ
β β β
ββββββββββββββββββββββββββββββΌβββββββββββββββββββΌβββββββββββββββββΌβββββββββ
β Privileged Capture β β β β
β Service (optional) β β βΌ β
β βββββββββββββββββββββββββββ΄ββββββββββ β βββββββββββββββββββ€
β β `netpulse-capture-svc` (bin) β β β Opt-in Egress β
β β or `netpulse-platform` (Npcap) β β β AI Assistant β
β βββββββββββββββββββββββββββββββββββββ β βββββββββββββββββββ
βββββββββββββββββββββββββββββββββββββββββββββββββΌββββββββββββββββββββββββββ
βΌ
Raw Network Interfaces / PCAP
For complete architectural specifications, see ARCHITECTURE.md.
- Rust 1.96+: Pinned in
rust-toolchain.toml. - Node.js 20+ & pnpm 9: Frontend workspace tools (
corepack enable). - Tauri CLI v2: Desktop app shell (
cargo install tauri-cli --version '^2'). - Npcap (Windows): Required for live capture (install with WinPcap API-compatible mode).
cargo build --workspace
cargo test --workspace
cargo run -p netpulse-engine -- path/to/capture.pcappnpm install
pnpm --filter @netpulse/contract typecheck
pnpm --filter @netpulse/app devcargo tauri devEverything below is local-only; nothing here opens an outbound connection.
| Variable | Effect |
|---|---|
NETPULSE_DB_PATH |
SQLite file backing the durable write-behind store (default: the per-user data directory). off disables persistence β the shell logs shell.persistence_disabled and health reports that this session is not persisted. |
NETPULSE_PCAP |
Seed the store from a saved capture instead of stored history for this run. |
NETPULSE_EXPORT_DIR |
Where StartExport writes JSON/CSV/HTML (default: <data dir>/exports). Every write is logged with its path and byte count, and the command returns the artifact (path, size, format, level) so the UI shows the real file instead of a generic success message. |
NETPULSE_BRIDGE_TOKEN |
Capability token for the loopback browser transport. Required by /api/query and /api/command (sent as X-NetPulse-Token); /api/health stays open. Without it the shell generates one and logs it as http_bridge.token. |
NETPULSE_SKIP_INTEGRITY_CHECK |
Skip the one-time PRAGMA integrity_check the durable writer runs at startup (useful for very large stores). |
The durable writer verifies database integrity once per session and reports dropped writes through Query::HealthCheck and the shutdown report; a silent write loss is a bug, not a mode.
The export screen can open the file it just wrote (Command::OpenExport): the UI passes back only the session-scoped artifact id the shell assigned, and the shell resolves that id to a file it wrote, inside the export directory, with an expected extension before handing it to the OS handler. A path is never accepted from the UI.
The bridge refuses requests whose Host is not a loopback origin, so a page that resolves an attacker-controlled name to 127.0.0.1 cannot reach the engine. To use the browser transport, start the shell, copy the logged token, and export the same value for the UI dev server:
NETPULSE_BRIDGE_TOKEN=<token from the shell log> pnpm --filter @netpulse/app devcrates/ 14 Rust workspace crates β engine, decode, flow, storage, intel, AI, API
ui/ pnpm workspace β app, contract, design-system, components, viz
src-tauri/ Tauri v2 desktop shell and IPC bridge
plugins/ First-party reference plugins (dissector, detector, enrichment, export, view)
fixtures/ Deterministic test capture files (.pcap / .pcapng)
fuzz/ cargo-fuzz targets for protocol dissectors
models/ Local ONNX model files and model cards
research/ Offline model training scripts (Python)
scripts/ Cross-platform build and release automation
data/ Local offline enrichment databases (GeoIP, ASN, MAC vendors)
ARCHITECTURE.mdβ System design, process model, and crate taxonomy.CONTRIBUTING.mdβ Development workflows, quality gates, and codegen.SECURITY.mdβ Security posture, isolation boundaries, and vulnerability reporting.CODE_OF_CONDUCT.mdβ Community standards and covenant.
Run local checks before pushing:
cargo fmt --all --check
cargo clippy --workspace --all-targets -- -D warnings
cargo test --workspace
python scripts/verify_docs_status.py
pnpm --filter @netpulse/contract typecheckDual-licensed under MIT or Apache-2.0.