Warning
Work in Progress
SpyCheck aims to detect spyware and stalkerware using passive network traffic analysis. It runs on a computer or laptop and creates a Wi-Fi hotspot or shared Ethernet connection, which the inspected device connects to.
- simple, readable, maintainable code
- non-invasive
- easy to install
- easy to use
- Requires NET_RAW capability
sudo setcap cap_net_raw+ep spycheck(ep = effective + permitted)
- No TLS decryption. TLS decryption requires adding a certificate authority to the system. (See the mitmproxy docs for an example.) This is a privacy risk and must be done with caution. Apps may detect it, and prevent it by using certificate pinning.
- Go (golang)
- NetworkManager
- libpcap
- web interface
- Alpine.js
- Bootstrap CSS
- PCAPdroid: local network traffic monitoring, inspection and recording on Android devices, including TLS decryption
- PiRogue: command-line toolkit for network traffic analysis using NFStream and Suricata, TLS decryption and smartphone forensics
- Sniffnet: local network traffic monitoring for Windows, macOS and Linux
- SpyGuard: fork of TinyCheck, outdated
- spytrap-wifi: command-line tool for a single board ARM computers, creates a Wi-Fi hotspot and checks for connections to stalkerware servers
- Suricata: intrusion detection system with custom rules, used by network administrators
- TinyCheck by Kaspersky Lab: abandoned
Funded from June to November 2025 by: