Protection active · pass-through build

See every connection
your Mac makes

A network observatory for macOS that shows you the evidence — every flow, every process, payload-free. Not a black box that cries wolf.

Notarized · Developer ID signed · macOS 15+ · Apple Silicon & Intel

Rocket Archipelago — Live Activity Shadow mode
18,432 flows attributed since 09:14
TimeProcessDestinationProtoVerdict
09:41:02com.apple.Safariedge.apple.com:443tcpallow
09:41:05Code Helperupdate.code.visualstudio:443tcpallow
09:41:09helperd UNSIGNEDauto.c3pool.org:443tcpshadow blockmining
09:41:11com.apple.nsurlsessiongateway.icloud.com:443tcpallow
09:41:14ssh10.40.0.12:22tcpflag
0payload bytes stored
UniversalApple Silicon + Intel
BSDlicensed, source open
Localno account, no server
Overview

Five components between the wire and the window

A signed system extension inspects every socket, a policy engine classifies it, and a private store keeps the evidence — never the payload.

System extension

A notarized NEFilterDataProvider sees every flow the moment it opens — before it leaves your Mac.

Threat policy engine

Priority rules match on destination, port, protocol, and the connecting process's real code signature. Mining pools and masqueraders get flagged.

Private event store

A bounded, payload-free record of what your Mac has been saying. Metadata and verdicts only — hostnames never logged in the clear.

GROUPING

Noise collapses

Thousands of routine connections become one process group, while unusual identities stay visible.

MENU BAR

Always watching, never loud

Close the window and inspection continues. Current health and controls remain one click away.

EXPORT

Evidence you can paste

Copy a readable process profile with verdict, signature, team identity, path, and observations.

Two modes

Watch, or experiment.
Never both by accident.

The two modes are separate systems, not a switch. Nothing in Lab mode can reach your live network.

Monitor

Passive, always safe. Attribute every connection to a process and a verdict.

  • Live flow attribution with real code-signature identity
  • Shadow policy — evaluates verdicts without blocking
  • Payload-free evidence you can copy and share

LabNative preview

Structured, authorized assessment modules from the modernized dsniff toolkit.

  • Five curated modules with fixed executable identities
  • Tokenized arguments, bounded output, and cancellation
  • Explicit ownership or authorization attestation
Process Knowledge Index

Evidence, not accusations

Every alert is backed by verifiable facts about the process — its signature, team identity, and behavior — so you decide, not a vendor's guess.

helperd UNSIGNED → auto.c3pool.org:443
No valid signature, no team identity, launched from a hidden support directory, connecting to a known mining pool.
Privacy

A network tool that never keeps your payloads

Archipelago records that a connection happened and to where — never what was in it. Everything stays local; nothing is uploaded.

No payloads, ever

The provider reads flow metadata only. Message bodies, form fields, and credentials are never captured.

Local-first

Evidence lives in a private, sandboxed store on your Mac. No telemetry leaves the device without your explicit configuration.

Notarized & open

Developer ID signed, Apple-notarized, and source-available so you can verify exactly what it does.

STOREDTimestamps, process identity, destination, port, protocol, and verdict
STOREDCode-signing identity, executable path, and bounded flow counters
NEVERPayload bytes, message bodies, form fields, credentials, or cookies
NEVERAnything uploaded to an Archipelago server — there is no account or cloud service
Security

Trust that can be checked

The app, extension, and data model expose the evidence behind their claims.

DISTRIBUTION

Signed and notarized

Developer ID signed by Rocket Now LLC, notarized by Apple, and stapled for offline verification.

BOUNDARY

Explicitly approved

The sandboxed Network Extension only activates after macOS presents its system approval flow.

AUDITABILITY

Source available

The control plane, policy engine, event schema, and redaction behavior live in the public repository.

Terminal Observatory

The same engine, without the window

Prefer the terminal? dsniff-tui gives you the full observatory as a keyboard-driven interface — free and open.

dsniff-tui — 132×40
 ARCHIPELAGO OBSERVATORY            mode: monitor   flows: 18,432
────────────────────────────────────────────────────────────
09:41:09  helperd            auto.c3pool.org:443   tcp  shadow-block
09:41:11  nsurlsessiond      gateway.icloud.com:443    tcp  allow
09:41:14  ssh                10.40.0.12:22             tcp  flag
────────────────────────────────────────────────────────────
[f]ilter  [i]nspect  [p]ause  [/]search  [q]uit
Pricing

Buy it once

No subscription. The terminal observatory is free and open; the Mac app is a one-time purchase.

Open source
Free

The terminal observatory, forever.

  • dsniff-tui terminal observatory
  • Native passive analyzers
  • Build from source
Read the source
Archipelago for Mac
$29

One time, no subscription.

  • SwiftUI dashboard & live console
  • Threat policy engine & signed policies
  • Menu-bar monitoring + notifications
  • Enforcement build when it lands
Download the DMG
FAQ

Questions people actually ask

Does it slow down my Mac?

No. The provider inspects flow metadata as connections open — it doesn't proxy or decrypt traffic, and it reads no payloads. In the default pass-through build it observes without blocking anything.

Can it read my messages or passwords?

No. Archipelago only sees that a connection happened and where to — never the contents. Payloads, form fields, and credentials are never captured or stored.

What is it standing on?

Archipelago modernizes dsniff for compatibility, distributed under the original BSD license. The passive analyzers are hardened, redacted rewrites of that classic toolkit.

Is my data uploaded anywhere?

No. Everything is local-first and stored in a sandboxed App Group container on your Mac. Nothing leaves the device unless you explicitly configure it to.

Does it block connections?

The current build runs in shadow mode — it evaluates policy and flags matches but never blocks, so it can't disconnect you. Enforcement is a separate, safety-gated build in development.

Launch

Find out what your Mac has been saying

Download the notarized DMG, or leave an email and we'll send the release notes when the enforcement build lands.