NetworkMonitor for Mac

Every byte. Accounted for.

Live network speed in your menu bar, and a straight answer to a question macOS never answers: which app used my data?

Version 1.1.0macOS 13 or laterApple silicon and IntelFree and open source

The macOS menu bar showing NetworkMonitor reading 2.42 MB/s down and 108.4 KB/s up, with its popover open: a 563.0 MB total, then Slack 162.4 MB, iTerm2 138.5 MB, Camoufox 71.3 MB, Google Chrome 51.8 MB, WhatsApp 27.6 MB, GoogleUpdater 18.7 MB, Code 5.0 MB and more.

The problem

Your Mac spends data behind your back.

Apps update themselves, sync and download whenever they like. On home broadband you never notice. On a phone’s hotspot you pay for every megabyte, and macOS keeps no running tally of which app spent it.

NetworkMonitor's popover with a 696.6 MB total. GoogleUpdater is third in the list at 135.0 MB, behind Slack at 162.4 MB and iTerm2 at 149.0 MB.
135 MB

Caught while this page was being made. GoogleUpdater went from 13.9 MB to 135 MB in about two minutes, in the background, on its own.

On home Wi‑Fi that was harmless. On a hotspot it would have been 135 MB of your plan, gone before you knew it had started.

Why it’s so hard to see.

01

Updaters run on their own schedule.

Chrome, VS Code, Microsoft AutoUpdate, apps built on Sparkle, and macOS itself fetch new versions whenever they decide to. Nothing tells you when.

02

One app hides behind a dozen names.

A browser runs a swarm of helper processes. A terminal launches git, ssh and command-line tools. In a raw process list, one app’s traffic is scattered across names you’ve never heard of.

03

Activity Monitor keeps a different clock.

It counts bytes since each process started, often days ago. It can’t tell you what the network you’re on right now has used.

04

Local traffic looks like internet traffic.

AirPlay to an Apple TV, Time Machine to a NAS, Plex from your own server. All of it crosses your Wi‑Fi, and none of it touches your data plan.

05

Hotspots are billed by the gigabyte.

Tethering is metered. If you only find out afterwards, when your carrier sends the warning, the data is already gone.

06

A traffic monitor sees everything.

Whatever watches your connections is in a position to report on them. It should ask for nothing, send nothing, and let you read every line.

The solution

Meet NetworkMonitor.

A small menu bar app that shows your speed live, tells you exactly which apps used this connection, and, if you ask it to, stops them updating while you’re on a hotspot. No Dock icon, no window to manage, no account.

See it live.

Download and upload speed, always in view, updated twice a second.

Know who used it.

Every app’s share of this connection, biggest first, with its own icon and bar.

Stop the surprise.

Automatic updates pause on hotspots and resume the moment you leave.

In the menu bar

Two lines.
Twice a second.

Download in green, upload in white: the same two arrows as the icon. The readout keeps a fixed width, so nothing beside it jitters as the numbers change, and it counts in bytes, the unit your data plan uses.

The real menu bar, mid-download.

One click

It’s live.
Not a snapshot.

Click the readout for this connection’s total and the apps behind it. The numbers move while you watch.

Screen recording · 10 s

Ten unedited seconds of the app, recorded off the screen. The total climbs as a download runs.

Sub-processes

Credit where it’s due.

Helpers fold into the app that owns them, so Chrome’s dozen helper processes are one Google Chrome row. Commands started from a terminal break out beneath it, each with its own figure.

The popover with iTerm2 expanded to show its sub-processes: 2.1.280 at 127.8 MB, 2.1.278 at 20.7 MB, git-remote-http at 355.8 KB and Other (4) at 237.3 KB.

System

macOS noise, folded away.

Dozens of system daemons collapse into a single System row at the bottom of the list. Open it when you’re curious; ignore it when you’re not.

The bottom of the popover's list: Software Update, Raycast, VoiceInk, Weather, IMTransferAgent, identityservicesd, Remote for Mac and Control Center, then a single System (35) row at 11.8 MB.

Sorted live

Biggest first.

Every app gets a bar for its share of the total, and the list re-sorts as apps overtake each other.

Per connection

One total per network.

Join a different Wi‑Fi or hotspot and the count starts from zero. Drop out and rejoin the same network and it picks up where it left off. It also resets at midnight, and survives restarts.

Internet only

Your LAN is free.

AirPlay, Time Machine to a NAS, Plex from your own server: they cross your Wi‑Fi but cost no internet data, so they’re never counted against you.

Hotspot mode

Hotspot on.
Updates off.

One setting. When you join a mobile hotspot, NetworkMonitor switches off your apps’ automatic updates, and switches them back on when you leave. Apps keep working. Chrome still browses, Slack still messages, VS Code still edits. They just don’t download new versions of themselves while you’re paying by the gigabyte.

NetworkMonitor Settings. Start at login is on. Under Hotspot, Stop apps updating on hotspots is on, with the note This connection isn't metered, and Apps paused (14) is expanded: Affinity, AppCleaner, ChatGPT, Claude Usage, Figma, Google Chrome, iTerm, macOS and in-app updaters, Microsoft AutoUpdate, OpenDisk, Remote for Mac, Visual Studio Code, VLC and VoiceInk.
Settings on the Mac this page was built on: 14 apps covered, each with its own switch.

Knows a hotspot when it joins one.

iPhone Personal Hotspot and Android tethering, over Wi‑Fi or USB, from your phone or someone else’s. Any network you’ve put in Low Data Mode counts too. Settings always tells you what it decided about the connection you’re on.

Covered with no special permissions.

Google ChromeVisual Studio CodeFigmaMicrosoft AutoUpdateVLCAppCleanerChatGPTAffinityVoiceInkany app using Sparkle

And with the optional helper.

macOS system updatesApp StoreClaudeSlackCanva

Run make helper once and enter your administrator password. The helper can do exactly three things: suppress, restore and report. The settings it touches are compiled into it, so it can’t be asked to change anything else.

Not a firewall.It changes each app’s own “check for updates automatically” setting. A manual Check for Updates… still works: it stops unattended downloads, not you.

Security updates pause too.There’s no reliable way to tell a security patch from a feature release, and pretending otherwise would be worse. Leave the hotspot or turn the setting off and everything resumes.

Puts everything back.make uninstall restores every setting exactly as it found it, then removes the app and the helper.

Measured, not estimated

Light enough to forget.
Accurate enough to trust.

99.6–100.2%

agreement with the kernel’s own byte counters, across three independent transfers.

0.1%

of one CPU core for live speed and your connection total, running all the time.

0.55%

of a core for per-app tracking, on every network and on battery. 256× less than earlier versions.

1 s · 3 s

Samples every second when plugged in, every three on battery. Same totals either way.

Per-app rows won’t quite add up to the connection total: some traffic is wire-level overhead that belongs to no app. The big total is the one to trust.

Privacy

It measures volume.
Never contents.

NetworkMonitor counts how much, never what. And it has no way to phone home.

No permission prompts.

It never asks for Location and doesn’t need it. The only thing that ever asks for your password is the optional hotspot helper, when you install it.

No network access.

The app makes no outbound connections of any kind. No analytics, no telemetry, no update check, no account.

Stays on your Mac.

Your usage lives in a single local file that you can delete at any time.

Open source.

MIT licensed. Read every line before you run it.

NetworkMonitor app icon: a green down arrow and a light up arrow on a dark rounded square.

Get NetworkMonitor.

Free and open source, for macOS 13 or later on Apple silicon and Intel. Two ways to install it.

Option 1

Download the app.

The usual Mac way: open the disk image and drag NetworkMonitor into Applications.

Download NetworkMonitor.dmg Version 1.1.0 · 1.6 MB · Universal
The NetworkMonitor disk image open in Finder: the title Install NetworkMonitor, the line Drag it into your Applications folder, and the app icon with a green arrow pointing to the Applications folder.
  1. Open NetworkMonitor.dmg and drag the app into Applications.
  2. Open NetworkMonitor from Applications. The first time, macOS says it can’t verify the app, because it isn’t signed with an Apple Developer ID yet. Click Done.
  3. Open System Settings › Privacy & Security, scroll down to Security, and click Open Anyway next to NetworkMonitor. Confirm with your password.
  4. Look for ↓↑ in your menu bar. You only do this once.

On macOS 13 or 14 there’s a shortcut for steps 2 and 3: Control-click the app in Applications, choose Open, then Open again.

Updating: download the new version and drag it over the old one. Removing: drag it to the Trash, but not while it’s pausing updates on a hotspot, or those apps stay paused.

Option 2

Build it with Terminal.

Compile it from source in one go. An app you build yourself is never quarantined, so there’s nothing to approve. You’ll need Apple’s Command Line Tools (xcode-select --install), not Xcode and not a developer account.

Terminal
$ git clone \
    https://github.com/kevinabouhanna/NetworkMonitor.git
$ cd NetworkMonitor
$ ./Scripts/install.sh

That builds the app, installs it in /Applications and starts it at login.

Update
make update
Skip the login item
./Scripts/install.sh --no-login
Optional hotspot helper
make helper
Uninstall, restoring every setting
./Scripts/uninstall.sh

Either way, the optional hotspot helper, which also pauses macOS, App Store, Claude, Slack and Canva updates, installs from Terminal: clone the repository and run make helper.