pinspect — Linux Process Intelligence CLI
Fast, deep Linux process inspection and forensic intelligence that goes far beyond
ps aux.
pinspect is an all-in-one terminal tool for systems engineers, SREs, and security investigators. It collects deep, actionable intelligence about running processes directly from native Linux /proc and kernel interfaces — zero external command dependencies, low overhead, graceful error recovery, and SIEM/EDR-ready output.
📦 Installation
Install with pipx (recommended — isolated environment):
pipx install pinspect-cli
Or with plain pip:
pip install pinspect-cli
⚡ Quick Start
pinspect ps # deep process list
pinspect show 1234 # full intelligence card for one PID
pinspect tree # process hierarchy
pinspect security 1234 # capabilities, seccomp, LSM + risk score
✨ Highlights
- Origin intelligence — detects systemd, cron, SSH, shell, Docker/Podman/Kubernetes, or kernel launch origins; resolves service units and container IDs
- Security forensics — decodes capability bitmasks, Seccomp, NoNewPrivs, AppArmor/SELinux, SetUID/SetGID, executable SHA-256 hashes, deleted-binary execution
- Risk scoring — every process gets a heuristic suspicion score (0–100) with explainable flags: deleted/memfd executables, RWX memory regions, dangerous capabilities, unsandboxed root
- Memory map forensics — flags code-injection evidence: W+X regions, anonymous executable mappings, fileless payloads, files deleted after mapping
- Files & sockets — open FDs, deleted files held open, per-PID or system-wide socket mapping
- Containers — list only containerized processes with runtime, container ID, and name
- Secret redaction —
envautomatically masks tokens, keys, passwords, and credentials - Built-in grep — search running processes by name, arguments, executable, or user; scriptable exit codes
- Interactive TUI — live dashboard with filtering, sorting, and multi-tab detail views
- SIEM / EDR formats — structured
--json,--csv,--quiet, and--wideon every subcommand
📖 Documentation
| Document | Contents |
|---|---|
| Installation | PyPI, pipx, and from-source installs |
| Command Reference | All 13 subcommands with examples |
| Output Formats | JSON, CSV, quiet, wide modes for pipelines |
| Security & Forensics | Risk scoring model, maps forensics, capability analysis |
🧪 Testing
python3 -m unittest discover -s tests -p "test_*.py" -v
📜 License
MIT — see LICENSE.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file pinspect_cli-1.0.3.tar.gz.
File metadata
- Download URL: pinspect_cli-1.0.3.tar.gz
- Upload date:
- Size: 60.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7814db9a953a864c35fdc72e501a8d357e66f4f10175af2cdb3d0644fb7eed35
|
|
| MD5 |
2237be7f11f7e45bc8048a577900b3c8
|
|
| BLAKE2b-256 |
cc5f47e5b8fc8872d5ff931fb269a50dae7dced5eac0cc2cf2290d42c6e23c76
|
Provenance
The following attestation bundles were made for pinspect_cli-1.0.3.tar.gz:
Publisher:
publish.yml on Baba01hacker666/pinspect
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
pinspect_cli-1.0.3.tar.gz -
Subject digest:
7814db9a953a864c35fdc72e501a8d357e66f4f10175af2cdb3d0644fb7eed35 - Sigstore transparency entry: 2571973784
- Sigstore integration time:
-
Permalink:
Baba01hacker666/pinspect@2d95e23d36167d016b7f934ee37de2e455668477 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/Baba01hacker666
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@2d95e23d36167d016b7f934ee37de2e455668477 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file pinspect_cli-1.0.3-py3-none-any.whl.
File metadata
- Download URL: pinspect_cli-1.0.3-py3-none-any.whl
- Upload date:
- Size: 79.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
32e78caaad8109e4ca13535a20dd2af67051bd056c1b2492e473e05f9cb883e3
|
|
| MD5 |
51ee308d50f5f540262a1ecd1e587ec9
|
|
| BLAKE2b-256 |
050572bcb466a40fe0f811f97ec2053ca551d258cb92c373ae5160acf769f11c
|
Provenance
The following attestation bundles were made for pinspect_cli-1.0.3-py3-none-any.whl:
Publisher:
publish.yml on Baba01hacker666/pinspect
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
pinspect_cli-1.0.3-py3-none-any.whl -
Subject digest:
32e78caaad8109e4ca13535a20dd2af67051bd056c1b2492e473e05f9cb883e3 - Sigstore transparency entry: 2571973845
- Sigstore integration time:
-
Permalink:
Baba01hacker666/pinspect@2d95e23d36167d016b7f934ee37de2e455668477 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/Baba01hacker666
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@2d95e23d36167d016b7f934ee37de2e455668477 -
Trigger Event:
workflow_dispatch
-
Statement type: