#1 Product of the week · Launched August 25, 2026
LAN Sheriff

LAN Sheriff

Nothing leaves town unnoticed 🤠 Every server your devices talk to, live on a world map. Self-hosted, open source, zero config.

FreeMonitoringCLIOpen Source9,263 impressions#1 of its week1 comment

Comments

>log in to comment
  • Zain Sheikh· 1mo ago

    The world map framing makes shadow telemetry obvious in a way that log tailing never does. Does it alert when a device starts talking to a destination it has never hit before?

A self-hosted network monitor that shows you, live on a world map, every server your devices are talking to, and flags the ones that don't belong. Includes Tailscale integration too, because at 291 Group, we love Tailscale! Run one binary. No account, no cloud, no configuration, no agent on any other device. It names the application behind each connection, shows where the traffic goes, and explains every suspicious finding in plain language instead of a score. Everything stays on your machine: it observes and never blocks, stores no payloads, and sends no telemetry. Deputy Mode needs no privileges at all. AGPL-3.0. From the makers of LAN Orangutan - 2nd place on Dev Hunt.

LAN Sheriff is a self-hosted, open-source tool that visualizes every outbound connection from your devices on a live world map.

for
Home users, hobbyists, and small-team IT admins who want privacy-first network visibility.
pricing
free
license
AGPL-3.0
291-Group/LAN-Sheriff 105 9Goupdated 16 days ago
works withTailscaleDiscordSlackntfywebhook

Key features

8 features of LAN Sheriff
  • Watchtower egress map — Shows a live world map with lines to every external server, including country, org, app and traffic details.
  • Deputy & Patrol modes — Runs without privileges on a single machine or with elevated access to monitor all devices on a network segment.
  • Radio Chatter DNS feed — Streams every DNS lookup with domain, resolver and classification of trackers or malware.
  • Precinct network map — Auto-generates a diagram of devices and their connections based on observed traffic.
  • Wanted List suspicion engine — Ranks and explains suspicious connections using plain-language reasons.
  • Dispatch peer sharing — Pairs multiple instances to aggregate observations without exposing raw traffic.
  • Export & alerts — Exports CSV/JSON and can send alerts to webhook, ntfy, Discord or Slack.
  • Multi-language UI — Interface available in 12 languages, including right-to-left scripts.

Use cases

  • Identify unknown trackers or telemetry services your smart TV contacts.
  • Detect compromised devices that start beaconing to suspicious servers.
  • Map the full network topology of a home lab or small office.
  • Audit which applications on a workstation are sending data to the internet.

LAN Sheriff vs alternatives

LAN SheriffLAN OrangutanOpenObservegroundcoverPulsetic
Best forLive outbound traffic mapNetwork scanningPetabyte-scale observabilityCloud observabilityUptime monitoring
PricingFreeFreeSubscriptionFreeFree
DevHunt upvotes32353939162
LaunchedAug 2026Jul 2026Apr 2026Feb 2024Jan 2024
  • LAN Sheriff vs LAN Orangutan: LAN Orangutan is a network scanner focused on host discovery, while LAN Sheriff visualizes live outbound traffic.
  • LAN Sheriff vs OpenObserve: OpenObserve provides large-scale observability pipelines, whereas LAN Sheriff is a lightweight local traffic monitor.
  • LAN Sheriff vs groundcover: groundcover offers cloud-focused observability metrics; LAN Sheriff runs locally and maps connections on a world map.
  • LAN Sheriff vs Pulsetic: Pulsetic monitors website uptime from multiple locations, while LAN Sheriff monitors all outbound traffic from your own devices.

LAN Sheriff FAQ

Do I need to create an account or use a cloud service?+

No, LAN Sheriff runs as a single binary locally with no account, cloud or telemetry.

Can it monitor traffic from other devices on my network?+

Yes, in Patrol mode you run the binary on a router, mirrored switch port, or any device that can see the traffic.

What permissions are required?+

Deputy mode needs no special privileges; Patrol mode requires elevated access to capture traffic.

Is any data sent outside my network?+

All observations stay on your machines; peer instances only exchange aggregated summaries over encrypted links.

Is LAN Sheriff open source?+

Yes, it is released under the AGPL-3.0 license and the source is on GitHub.

Can I export the collected data?+

You can export any view as CSV or JSON for further analysis.

Summarized by DevHunt from lansheriff.com · Sep 27, 2026. Details may change; check the official site.