Skip to content
FreeSnitch Download

Outbound visibility for macOS

See every connection.

FreeSnitch is an open-source macOS firewall that shows where processes connect and lets you decide what happens next.

Version 1.0.0 macOS 13+ Apple Silicon and Intel Notarized

FreeSnitch Network Monitor: apps with their traffic, a world map of where it goes, and a summary of the busiest apps, domains and countries
The monitor brings destinations, processes, and byte counts into one view.

Start with a map, not a mystery.

See active connections in real time, grouped by process and destination. Geolocation stays offline, and FreeSnitch collects no telemetry.

Cost
Free to use
Collection
Zero telemetry
Platform
macOS 13+, Apple Silicon and Intel
Network Monitor in light mode with Arc expanded to show each destination it reached, including one denied tracker, next to the world map
A live view of the connections that are easy to miss in an ordinary network menu.

The useful detail is per process.

A destination means more when you can see which app reached it and how much data moved. FreeSnitch keeps that context next to the map.

Process
Identify the app that opened the connection.
Destination
Inspect the hostname, address, and port.
Traffic
Read the bytes moving through each process.

When something reaches out, the choice is yours.

Connection alerts turn an unfamiliar outbound request into a decision you can inspect, narrow, and remember.

A rule should match the question you are asking.

Allow or deny the request, then choose how much of the future to cover. Keep a one-off decision temporary, or make a clear rule that lasts.

Connection alert: Discord wants to connect to gateway.discord.gg on port 443, with Remember, Applies to and Expires choices and Deny or Allow
The alert says who is asking, for what, and what the answer will create.
  1. A process connects

    FreeSnitch identifies the process, destination, address, and port before you decide.

  2. You set the boundary

    Scope the decision to the process, domain, IP, or port. Choose 5 minutes, 1 hour, or forever.

  3. The decision persists

    Priority ordering keeps broad and narrow rules understandable in the Rules Manager.

Alert
Ask before an unapproved connection leaves the Mac.
Silent Allow
Let matching traffic pass without interrupting you.
Silent Deny
Reject matching traffic without opening an alert.

Set boundaries that make sense to you.

The Rules Manager turns decisions into a policy you can inspect. Other controls cover the paths that names alone cannot.

Rules: allow, deny and ask rules per app and destination, with the blocklists in force
Rules stay visible as policy, not hidden as a series of one-time prompts.

The rule stays legible.

Use glob hostnames, CIDR ranges, and ports. Search the fields you care about, then let priority ordering make the match explicit.

The map helps you notice. The Rules Manager helps you make the decision repeatable.

DNS over HTTPS
Choose Cloudflare, Quad9, Google, or a custom endpoint. A local proxy listens on 127.0.0.1:53.
Blocklists
Subscribe to 1Hosts, OISD, StevenBlack, or HaGeZi, with scheduled refreshes. With Enforcement enabled, they filter DNS names sent through FreeSnitch's proxy, not hardcoded IP addresses or names resolved through an app's own encrypted DNS, such as Chrome and Firefox DoH.
pfctl anchor
Apply kernel-level IP, CIDR, and port blocking through a pfctl anchor.
Offline city-level geolocation
Place active IPv4 and IPv6 connections on the map, down to the city, without sending location lookups to a third party. The database is downloaded once in bulk and refreshed monthly; individual addresses are never sent anywhere. Where only the country is known, the endpoint is shown at the country centroid and labelled as country level. IP Geolocation by DB-IP.

A firewall should explain its own limits.

FreeSnitch separates visibility, policy, and enforcement so you can see what the app can do before you rely on it.

It fails open by design.

If the GUI is not running or does not answer, traffic is allowed rather than blocked. That keeps a broken interface from becoming a connectivity outage.

Network System Extension
FreeSnitch is a per-process outbound application firewall built on a Network System Extension.
Privileged helper
The helper handles the system-level work while the GUI presents decisions and policy.
Data collection
No telemetry, analytics SDK, or license check. Connection geolocation is offline.
Distribution
The release is signed with a Developer ID, notarized and stapled by Apple. Updates arrive through Sparkle and are checked against an EdDSA signature before they install.

The differences are practical.

FreeSnitch sits between a full outbound firewall and the narrow protection built into macOS. Here is the shape of that choice.

Comparison of FreeSnitch with Little Snitch, LuLu, and the macOS Firewall
Capability FreeSnitch Little Snitch LuLu macOS Firewall
Cost Free Paid Free Included
Outbound application firewall Per process Per process Per process Inbound only
Live world map and byte counts Yes Yes No No
Scoped connection alerts Yes Yes Yes No
Rules for host, CIDR, and port Yes Yes Limited No
DNS over HTTPS and local proxy Yes Yes No No
Blocklists with scheduled refresh Yes Yes No No
Source license MIT Proprietary GPL Proprietary

FreeSnitch column as of version 1.0.0. Per-process filtering runs in a Network System Extension that macOS asks you to approve on first launch.

Know where it stops.

Version 1.0.0 is signed, notarized, and ready to install. Here is what it does not cover, said up front.

Blocklists are DNS only

Lists filter domain names through the local DNS proxy. They do not stop connections to hardcoded IP addresses, or names an app resolves with its own encrypted DNS, such as Chrome and Firefox with DoH on.

The map is an estimate

Locations come from offline IP geolocation, not measurement.

Enforcement is opt-in

Out of the box FreeSnitch watches. The DNS proxy and pf rules start only when you turn on Enforcement in Settings.

Install it. Approve only what you understand.

One universal disk image for macOS 13 or later, on Apple Silicon and Intel. Signed with a Developer ID and notarized by Apple.

FreeSnitch-1.0.0.dmg, 13.7 MB. Free, no account.

  1. 01

    Drag to Applications

    Open the disk image and drag FreeSnitch into Applications. macOS only installs its helper from there.

  2. 02

    Allow the helper

    System Settings / General / Login Items & Extensions. Turn on Allow in the Background for FreeSnitch.

  3. 03

    Approve the filter

    When macOS asks, allow the FreeSnitch system extension in System Settings. It does the per-process filtering.

Check the download before you open it:

shasum -a 256 ~/Downloads/FreeSnitch-1.0.0.dmg
610ef02c2201dba159172f774fd22fa88f6cbc3b79449bef9dacaab5ce361044

Read the source before you trust the filter.

FreeSnitch is free to inspect, fork, and improve. Source, issues, contribution notes, and the MIT license live in the repository.

Project origin

FreeSnitch is an independently maintained fork of PureSnitch created by Moamen Basel. It is MIT licensed. Moamen Basel does not maintain or endorse this fork.