Skip to content

Latest commit

 

History

12 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

pinspect — Linux Process Intelligence CLI

Fast, deep Linux process inspection and forensic intelligence that goes far beyond ps aux.

PyPI version Python versions License: MIT

pinspect is an all-in-one terminal tool for systems engineers, SREs, and security investigators. It collects deep, actionable intelligence about running processes directly from native Linux /proc and kernel interfaces — zero external command dependencies, low overhead, graceful error recovery, and SIEM/EDR-ready output.

📦 Installation

Install with pipx (recommended — isolated environment):

pipx install pinspect-cli

Or with plain pip:

pip install pinspect-cli

⚡ Quick Start

pinspect ps                 # deep process list
pinspect show 1234          # full intelligence card for one PID
pinspect tree               # process hierarchy
pinspect security 1234      # capabilities, seccomp, LSM + risk score

✨ Highlights

  • Origin intelligence — detects systemd, cron, SSH, shell, Docker/Podman/Kubernetes, or kernel launch origins; resolves service units and container IDs
  • Security forensics — decodes capability bitmasks, Seccomp, NoNewPrivs, AppArmor/SELinux, SetUID/SetGID, executable SHA-256 hashes, deleted-binary execution
  • Risk scoring — every process gets a heuristic suspicion score (0–100) with explainable flags: deleted/memfd executables, RWX memory regions, dangerous capabilities, unsandboxed root
  • Memory map forensics — flags code-injection evidence: W+X regions, anonymous executable mappings, fileless payloads, files deleted after mapping
  • Files & sockets — open FDs, deleted files held open, per-PID or system-wide socket mapping
  • Containers — list only containerized processes with runtime, container ID, and name
  • Secret redaction — env automatically masks tokens, keys, passwords, and credentials
  • Built-in grep — search running processes by name, arguments, executable, or user; scriptable exit codes
  • Interactive TUI — live dashboard with filtering, sorting, and multi-tab detail views
  • SIEM / EDR formats — structured --json, --csv, --quiet, and --wide on every subcommand

📖 Documentation

Document Contents
Installation PyPI, pipx, and from-source installs
Command Reference All 13 subcommands with examples
Output Formats JSON, CSV, quiet, wide modes for pipelines
Security & Forensics Risk scoring model, maps forensics, capability analysis

🧪 Testing

python3 -m unittest discover -s tests -p "test_*.py" -v

📜 License

MIT — see LICENSE.

About

⚡ Fast Linux process-intelligence CLI & forensics tool that goes far beyond 'ps aux'. Inspects origin, capabilities, FDs, sockets, namespaces, secrets, and process trees with SIEM/EDR JSON and interactive TUI.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages