A CO-RE program mirrors traffic straight out of the kernel ring buffer — the lowest overhead path available, with automatic fallback so it's never a single point of failure.CO-RE 程序直接从内核 ring buffer 镜像流量 —— 开销最低的路径,且有自动回退,永远不是单点故障。
Every packet becomes a coloured pulse in a live field — rendered on the GPU when CUDA is present, with a CPU path that is bit-for-bit identical when it isn't.每个数据包在实时色场里是一次彩色脉冲 —— 有 CUDA 就上 GPU 渲染,没有就走逐位一致的 CPU 路径。
Field-tree layer names, hex dump, filter syntax — all lifted from Wireshark's own conventions. If you already know one, you already know the other.字段树的层名、十六进制视图、过滤器语法,全部沿用 Wireshark 的习惯——用过一个,另一个就不用学。
Everything inside the dashed line runs on the same host that already routes your network. The only thing that ever calls out is a timed threat-intel refresh.虚线以内的一切,都跑在已经帮你路由的这台机器上——真正联网的,只有定时拉取一次威胁情报这一件事。
Separate binaries, separate frontends. Suspend the analyzer mid-investigation and the overview's API doesn't even notice — it keeps logging on its own.各自独立的二进制、独立的前端。把分析器进程挂起,总览的 API 完全不受影响,照常记录。
Stays open in a tab, all day: devices, alerts, by-IP / by-protocol breakdowns, traffic trends over time — plus an offline pcap-analysis tab when something needs a closer look.常年开着的一个标签页:设备、告警、按 IP / 按协议拆解、流量走势,外加一个离线 pcap 分析页签,遇到问题随时细查。
Wireshark-style triple pane — packet list, protocol field tree, hex dump — with a display-filter language, JA3, process attribution and a GPU-rendered colour field for the traffic itself.Wireshark 式三窗格:包列表、协议字段树、十六进制视图,另外还有显示过滤器语言、JA3 指纹、进程归属,和 GPU 渲染的流量色场。
Every capability below runs today — nothing here is a roadmap slide.下面每一项都已经在跑,没有一条是路线图空谈。
A CO-RE kernel program mirrors whole frames off the wire with the lowest per-packet overhead available. Falls back to raw-socket AF_PACKET, then a clearly labeled simulator — never passed off as real.CO-RE 内核程序以最低的单包开销镜像完整帧;失败则回退到 AF_PACKET,再回退到明确标注的模拟场景 —— 绝不冒充真实流量。
Ethernet through application layer: DNS/mDNS, TLS (SNI, ALPN, JA3), HTTP, MQTT, SSDP, DHCP, CoAP — decoded field by field, not just identified.从以太网到应用层:DNS/mDNS、TLS(SNI/ALPN/JA3)、HTTP、MQTT、SSDP、DHCP、CoAP —— 逐字段解析,不只是识别协议名。
A Wireshark-compatible subset — logic, comparisons, CIDR, regex — driven by the same parser that validates and filters, so there is never a second syntax to drift out of sync.兼容 Wireshark 语法子集 —— 逻辑运算、比较、CIDR、正则 —— 校验和实际过滤走的是同一个解析器,不会出现两套语法各说各话。
Threat intel, beaconing, fan-out/scan, lateral movement, DNS anomalies, geo anomalies, off-hours activity, and a z-score behavior baseline — scored and thresholded, not a black box.威胁情报、信标、扇出/扫描、横向移动、DNS 异常、地域异常、非常规时段、z-score 行为基线 —— 加权评分,阈值可调,不是黑箱。
Hue encodes protocol identity, brightness encodes magnitude — rendered on CUDA when available, or an identical CPU path, bit-verified to agree.色相编码协议身份、亮度编码强度 —— 有 CUDA 就用 GPU 渲染,没有就用 CPU 路径,两者逐位一致。
Maps a local flow to the owning process by inode — and refuses to attribute another device's traffic rather than guess. Domains learned live from DNS/SNI/mDNS, never reverse-resolved.本机的流量,按 socket inode 精确对应到进程;别的设备呢,宁可不认,也不瞎猜。域名全靠 DNS/SNI/mDNS 现学现用,从不做反向解析。
Upload any capture: TCP stream reassembly, credential extraction, file carving, and heuristic attack-pattern findings — every finding labeled as a heuristic, not a verdict.上传任意抓包:TCP 流重组、凭证提取、文件提取、启发式攻击模式发现 —— 每一条结论都标注为启发式判断,不是定论。
Trigger a bounded, MAC-filtered capture on demand, distinct from the rolling buffer's export. A USB NIC appearing or disappearing is picked up live, no restart.按需触发一次限时、按 MAC 过滤的定向抓包,区别于滚动缓冲的导出。USB 网卡插拔实时响应,无需重启。
A real public blocklist (CIDR-matched), refreshed on a timer with a local cache — and GeoIP looked up entirely against a local database, never a third-party API call per IP. The overview now plots it on a rotating 3D globe too, rendered live in your browser's own GPU (WebGL2), destinations lighting up as the traffic actually happens.接入真实公开黑名单(CIDR 匹配),定时刷新并本地缓存;GeoIP 查询全程离线,绝不逐 IP 调用第三方 API。总览页面现在还会把这些坐标画在一个可旋转的 3D 地球上,用你浏览器自己的 GPU 实时渲染(WebGL2),流量发生的地方会跟着亮起来。
The gateway sees every device on the network the same way — what you use it for depends on which device you're looking at.网关对每一台设备一视同仁——它能派上什么用场,看你在盯着哪一台。
Laptops, phones, tablets, the smart bulbs and cameras nobody remembers pairing — one dashboard, not just the IoT corner of it.笔记本、手机、平板,还有那些配对之后再没想起过的智能灯泡和摄像头——都在同一张图里,不会被单独归到"IoT 角落"。
SNI, ALPN, JA3, and full plaintext bodies for HTTP/MQTT — see what your laptop or phone actually sent, without a proxy certificate on the device under test.SNI、ALPN、JA3,加上 HTTP、MQTT 的完整明文内容——笔记本或手机到底发出去了什么,一目了然,不需要在被测设备上装任何代理证书。
A guest's phone, a roommate's speaker, a contractor's laptop — anything on the LAN is visible the moment it talks, without asking anyone to install a thing.访客的手机、室友的音箱、装修师傅的笔记本——只要接进这个局域网、发出第一个包,就能被看到,不需要谁配合装任何东西。
Upload a capture and get TCP stream reassembly, extracted credentials and files, JA3 fingerprints, and heuristic attack-pattern findings — the same first pass a protocol reverse-engineering or incident-response workflow starts with. Any interface name works, not just wlan0/eth0 — including the tun device an SDR software base station (srsRAN, OAI, Amarisoft) hands you once a UE attaches, so the same pipeline reads 4G/5G user-plane traffic without a line of new code.上传一份抓包,就能拿到 TCP 流重组、提取出的凭证和文件、JA3 指纹,还有规则命中的可疑攻击模式——协议逆向、应急响应,动手前的第一步大多就是这些。网卡名不限于 wlan0/eth0——SDR 软基站(srsRAN、OAI、Amarisoft)一旦有 UE 附着,用户面流量就落在一块 tun 网卡上,接上去就是普通网卡,同一套流水线直接读 4G/5G,不用改一行代码。
The gateway can optionally read the plaintext of TLS traffic from processes running on itself, by attaching a uprobe to their own OpenSSL library at runtime. No certificate is installed anywhere, nothing is forged, and nothing on the network is intercepted — it reads memory the process already decrypted for its own use.网关可以选择性地读取它自己本机进程的 TLS 明文 —— 做法是在运行时给该进程自己的 OpenSSL 库挂一个 uprobe。不装任何证书、不伪造任何东西、也不拦截网络上的任何流量,只是读取进程自己已经解密好、正在使用的那块内存。
Off by default. It cannot reach a camera, lock or phone — those decrypt on their own hardware, which this never touches.默认关闭。摄像头、门锁、手机都碰不着——它们各自在自己的硬件上解密,这项能力压根伸不到那儿。
A second, separate exception:第二个、独立的例外: A phone or computer can opt into full HTTPS decryption by installing this gateway's own root certificate — the Surge/Burp/mitmproxy model, not a MITM anyone is subjected to without asking. Nothing without that certificate installed, ever gets decrypted; see the "Certificate & decryption" page in the overview UI.一台手机或电脑,可以主动装上这个网关自己生成的根证书,让自己的 HTTPS 被完整解密——用法跟 Surge、Burp、mitmproxy 一样,不是强加给谁的 MITM。没装证书的设备,永远不会被解密;入口在总览 UI 的"证书与解密"页面。
SNI, ALPN and JA3 come from the handshake, which is plaintext by design — nothing else is touched.SNI、ALPN、JA3 全部来自握手阶段本就明文的部分,其余内容不做任何触碰。
Looked up against an on-disk database. Destination IPs are never sent to a third party one by one.对照本地数据库查询,目的 IP 绝不逐条发往第三方。
Lock and camera activity is never uploaded anywhere — it lives in this box's own SQLite database.门锁与摄像头的活动记录不上传到任何地方,只存在这台机器自己的 SQLite 数据库里。
Names are learned only from traffic your network already generated — DNS answers, TLS SNI, mDNS. Never a lookup that leaks where you're headed.设备名称只从网络自己产生的流量里学——DNS 应答、TLS SNI、mDNS,从不主动查询,因为查询本身就会暴露你要去哪。
| Component组件 | Minimum最低要求 |
|---|---|
| OS / kernel操作系统 / 内核 | Linux ≥ 5.8 (BTF) · TCX ≥ 6.6 |
| Go | ≥ 1.25 |
| clang | ≥ 11 |
| Node.js | ≥ 18 |
| CUDA toolkitCUDA 工具链 | optional — identical CPU path always available可选 —— CPU 路径始终可用且结果一致 |
No. BeeEye attaches to the LAN-side interface of your router/gateway box only. Every other device on the network is observed passively.不需要。BeeEye 只挂载在路由/网关主机的 LAN 侧接口上,网络里的其它设备全部被动观察。
It falls back to a built-in simulated scenario and says so — in the startup log and in the UI's live source badge. It never presents simulated data as real.会回退到内置模拟场景,并在启动日志和界面的数据来源角标里明确标注 —— 绝不把模拟数据当真实数据呈现。
Yes — a thin desktop shell wraps the same live-analyzer UI in a native window, so it opens like any other app instead of a browser tab.可以 —— 一个轻量桌面外壳把同一套实时分析器界面包进原生窗口,像普通应用一样打开,而不是浏览器标签页。
Two binaries, two ports, one repo. No account, no cloud dependency, no telemetry. 两个二进制、两个端口、一个仓库。无需账号、无云端依赖、无遥测。
Everything above this line ships today. What's below is written down in this project's own progress log the same way — a real gap, not a "someday."这条线以上,现在就能用。线下这几条,项目自己的进度记录里写得明明白白——是实打实的缺口,不是随口一句"以后再说"。
uprobe plaintext capture covers OpenSSL today. GnuTLS, NSS and Go's crypto/tls are next, plus pcapng+DSB export so a capture and its keys travel in one file.目前 uprobe 明文捕获只覆盖 OpenSSL。GnuTLS、NSS、Go crypto/tls 是下一步,外加 pcapng+DSB 导出,让抓包文件和密钥装进同一个文件里。
DHCP/mDNS/SSDP fingerprints are already collected. Matching them against a real model database, not just the OUI's first three bytes, is what's missing.DHCP/mDNS/SSDP 指纹已经在采集。接入一个真正的型号数据库做比对,而不只是靠 OUI 前三字节猜,是目前缺的一环。
High-rate NXDOMAIN (DGA-style) is caught today. Spotting data smuggled through the query names themselves is a different signature, not built yet.高频 NXDOMAIN(疑似 DGA)已经能抓到。识别"数据本身藏在查询名字里"这种偷渡方式,是另一套特征,还没做。
An XDP program that only lets a lock or camera talk to the endpoints it's supposed to — blocking, not just alerting after the fact.用 XDP 程序限定门锁、摄像头只能和该联系的地址通信——是真的拦截,不是事后才告警。
Neither needs a live capture backend, on reflection — Android's developer options export a standard btsnoop-format Bluetooth HCI log directly off the phone, and SIMtrace already writes its own log file rather than requiring a live tap. Both are the same shape of problem as the offline pcap analysis above: upload a file, parse it. What's actually missing is a decoder for each format, not a new capture path. Cellular is a separate story: see "Security research & audits" above — an SDR software base station's user-plane traffic already lands on an ordinary tun interface, and that one just works today.细想下来,这两个其实都不需要实时抓包后端——Android 开发者选项能直接从手机导出标准 btsnoop 格式的蓝牙 HCI 日志;SIMtrace 本身也会落一份自己的日志文件,不需要接在线的探针实时抓。这两个跟上面的离线 pcap 分析是同一类问题:上传文件、解析它。真正缺的是各自格式的解码器,不是一条新的抓包路径。蜂窝网络是另一回事:见上面"安全研究与审计"那张卡片——SDR 软基站的用户面流量本来就落在一块普通的 tun 网卡上,这个现在就能用。