witr

A command line and terminal UI tool that answers why something is running. It traces a process, port, container or file back to what started it, which helps with troubleshooting and incident response.

Share on XLicense: Apache-2.0

Overview

witr is a command line and terminal UI tool that answers one question: why is this running? Given a process, port, container or file, it traces back to the chain that started it, across supervisors, containers, services and shells. Tools like ps, lsof, ss and docker ps show what is running, but you must piece together the cause yourself. witr makes that cause explicit, with readable output, JSON or an interactive TUI.

Key features

  • Traces processes, ports, containers and files to their origin
  • Explains the chain through supervisors, containers and services
  • Offers machine-readable JSON output
  • Includes an interactive terminal UI
  • Has a browser-based tutorial sandbox

Best for

Engineers troubleshooting an unexpected process or open port, and people doing incident response on a Linux system.

Upstream
pranshuparmar/witr
Fork on GitHub
Guo-astro/witr
Upstream stars
23k
Category
Developer tools and infrastructure
Language
Go
License
Apache-2.0
Forked
2026-01-02
Sync status
In sync, has own commitsLast synced 2026-09-29