Keeping tabs on your systems..
Snitch is a tool designed to provide a common interface for monitoring system activity. It uses a plugin-based system to check for signs of life, such as file modifications or the output of custom functions. This allows you to get a quick and simple "active" or "inactive" status for a machine.
Snitch offers a few simple commands to manage activity checks and view status.
To run a new activity check, use the check command. This will execute all configured plugins, update the local state file with the results, and print the current status.
Note: You'll likely want to run this with a user that has root permissions to make sure it has access to each file.
snitch checkTo view the most recent activity status without running a new check, use the status command.
snitch statusExample output:
--- System Activity Status ---
Status: ACTIVE (within last 5 days)
Confidence: 100.0%
Last File Activity: 2025-09-19 10:30:00
Last Checked: 2025-09-19 10:30:00
Snitch can run as a simple HTTP server to expose the latest activity status via a JSON API. Use the serve command for this.
snitch serve --port 8000This will start a server on port 8000. You can then query the API to get the status:
curl http://localhost:8000/