Description
Per-application network activity can be monitored with BPF-based process tracking. This system monitoring tool is useful for users who want to see which executables connect to the network and how much traffic they generate. It is run from a terminal with the picosnitch command. Network logs can reveal private app use, destinations, and timing, and BPF monitoring may require elevated privileges.