evillimiter is a free, open source threat detection & response project written in Python and released under MIT. It has 2,024 GitHub stars, 365 forks and 28 open issues, and was last pushed 7 months ago. On this registry it ranks #40 of 59 tracked projects in Threat Detection & Response, with 5 head-to-head comparisons available.

What is evillimiter?

Evil Limiter is a command-line tool for Linux that lets a network administrator or pentester monitor, analyze, throttle, and block the bandwidth of individual devices on their local network without physical or administrative access to those devices.

What it is

Evil Limiter is a Python 3 command-line utility released under the MIT licence and published in the Security & Privacy / Threat Detection & Response category. It targets the local network an operator is themselves connected to, discovering hosts, tracking their traffic, and applying upload and download restrictions from an interactive shell. It lives in the Linux networking and security-tooling ecosystem, where it depends on ARP spoofing to intercept traffic and on tc traffic shaping to enforce the resulting rate limits.

The concrete problem it solves is congestion control over devices you can see but do not administer: a housemate's saturated video stream, a guest hogging the office uplink, or a suspect host during an engagement. Where the alternative is logging into a router with administrative credentials — or logging into each client machine — Evil Limiter instead positions itself between the target and the gateway, shaping packets as they pass. It resolves the network interface, netmask, and gateway address automatically, so the operator does not need to supply that configuration by hand, and it can flush the current iptables and tc configuration with the -f flag to ensure packets are dealt with correctly.

Key capabilities

  • Scans the network for online hosts with scan, optionally restricted to a custom range such as scan --range 192.168.178.1-192.168.178.40, or across the entire subnet.
  • Lists scanned hosts in a table with hosts, assigning each an ID used to address it in later commands; --force prints the table even when it does not fit the terminal.
  • Throttles bandwidth with limit [ID1,ID2,...] [Rate], accepting bit, kbit, mbit, and gbit rates and either --upload or --download direction, for example limit 4,5,6 200kbit or limit all 1gbit.
  • Cuts connectivity entirely with block [ID1,ID2,...], again direction-selective, and restores it with free [ID1,ID2,...], which removes all restrictions.
  • Adds a host manually by IP with add [IP], resolving its MAC address automatically or accepting it explicitly with --mac.
  • Reports live bandwidth usage of limited hosts through monitor, refreshing at a configurable --interval in milliseconds (default 500 ms).
  • Takes network parameters explicitly via -i (interface), -g (gateway IP), -m (gateway MAC), and -n (netmask) when auto-resolution is not wanted, with --colorless to disable coloured output.

Who uses it and how

  • A home or small-office administrator throttling a single device from an interactive session after running scan and reading IDs off the hosts table, for example limit all 1gbit.
  • A penetration tester or red-team operator running it as part of the pentest toolchain implied by its pentesting and penetration-testing project topics, using block and free to control access during an engagement.
  • An operator on a Linux laptop who must specify the active interface with -i and the gateway details with -g and -m when the host sits on an unusual network topology.
  • Anyone tracking consumption over time who repeatedly invokes monitor --interval 1000 while limits are in force to watch current and total usage.
  • A Windows user running the separate open-source EvilLimiter for Windows port instead, since this build requires a Linux distribution.

Getting started

Clone the repository with git clone https://github.com/bitbrute/evillimiter.git, install it with sudo python3 setup.py install, and launch it with evillimiter or python3 bin/evillimiter; alternatively download a version from the project's release page.

How it compares

Evil Limiter's Windows counterpart, EvilLimiter for Windows, is the named alternative for operators not on Linux, and this project is the Linux-native original behind it. Nothing else in this registry's facts covers the same ARP-spoofing-based local bandwidth-shaping role on Linux.

When to use it — and when not

It is the right choice when you are already on the target LAN with root-equivalent access on a Linux host — the tool manipulates iptables and tc and performs ARP spoofing, and it requires a Linux distribution with Python 3. It is not appropriate against hosts on other subnets, against IPv6-only networks, or on Windows without switching to the separate port, and it should not be used without authorisation on networks you do not manage. Bear in mind that ARP spoofing is detectable and disruptive if a limit is left applied, and that 28 open issues remain on the repository.

project readme (upstream, from github) — read inline

Evil Limiter

License Badge Compatibility Maintenance HitCount Open Source Love

A tool to monitor, analyze and limit the bandwidth (upload/download) of devices on your local network without physical or administrative access.

evillimiter employs ARP spoofing and traffic shaping to throttle the bandwidth of hosts on the network.

Searching for a Windows-compatible version?
Check out the open-source alternative EvilLimiter for Windows.

Requirements

  • Linux distribution
  • Python 3 or greater

Possibly missing python packages will be installed during the installation process.

Installation

git clone https://github.com/bitbrute/evillimiter.git
cd evillimiter
sudo python3 setup.py install

Alternatively, you can download a desired version from the Release page.

Usage

Type evillimiter or python3 bin/evillimiter to run the tool.

evillimiter will try to resolve required information (network interface, netmask, gateway address, ...) on its own, automatically.

Command-Line Arguments
Argument Explanation
-h Displays help message listing all command-line arguments
-i [Interface Name] Specifies network interface (resolved if not specified)
-g [Gateway IP Address] Specifies gateway IP address (resolved if not specified)
-m [Gateway MAC Address] Specifies gateway MAC address (resolved if not specified)
-n [Netmask Address] Specifies netmask (resolved if not specified)
-f Flushes current iptables and tc configuration. Ensures that packets are dealt with correctly.
--colorless Disables colored output
evillimiter Commands
Command Explanation
scan (--range [IP Range]) Scans your network for online hosts. One of the first things to do after start.
--range lets you specify a custom IP range.
For example: scan --range 192.168.178.1-192.168.178.40 or just scan to scan the entire subnet.
hosts (--force) Displays all the hosts/devices previously scanned and basic information. Shows ID for each host that is required for interaction.
--force forces the table to be shown, even when it doesn't fit the terminal.
limit [ID1,ID2,...] [Rate] (--upload) (--download) Limits bandwidth of host(s) associated to specified ID. Rate determines the internet speed.
--upload limits outgoing traffic only.
--download limits incoming traffic only.
Valid rates: bit, kbit, mbit, gbit
For example: limit 4,5,6 200kbit or limit all 1gbit
block [ID1,ID2,...] (--upload) (--download) Blocks internet connection of host(s) associated to specified ID.
--upload limits outgoing traffic only
--download limits incoming traffic only.
free [ID1,ID2,...] Unlimits/Unblocks host(s) associated to specified ID. Removes all further restrictions.
add [IP] (--mac [MAC]) Adds custom host to host list. MAC-Address will be resolved automatically or can be specified manually.
For example: add 192.168.178.24 or add 192.168.1.50 --mac 1c:fc:bc:2d:a6:37
monitor (--interval [time in ms]) Monitors bandwidth usage of limited host(s) (current usage, total bandwidth used, ...).
--interval sets the interval after bandwidth information get refreshed in milliseconds (default 500ms).
For example: monitor --interval 1000
analyze [ID1,ID2,...] (--duration [time in s]) Analyzes traffic of host(s) without limiting to determine who uses how much bandwidth.
--duration specifies the duration of the analysis in seconds (default 30s).
For example: analyze 2,3 --duration 120
watch Shows current watch status. The watch feature detects when a host reconnects with a different IP address.
watch add [ID1,ID2,...] Adds specified host(s) to the watchlist.
For example: watch add 6,7,8
watch remove [ID1,ID2,...] Removes specified host(s) from the watchlist.
For example: watch remove all
watch set [Attribute] [Value] Changes current watch settings. The following attributes can be changed:
range is the IP range to scan for reconnects.
interval is the time to wait between each network scan (in seconds).
For example: watch set interval 120
clear Clears the terminal window.
quit Quits the application.
?, help Displays command information similar to this one.

Restrictions

  • Limits IPv4 connctions only, since ARP spoofing requires the ARP packet that is only present on IPv4 networks.

Disclaimer

Evil Limiter is provided by bitbrute "as is" and "with all faults". The provider makes no representations or warranties of any kind concerning the safety, suitability, lack of viruses, inaccuracies, typographical errors, or other harmful components of this software. There are inherent dangers in the use of any software, and you are solely responsible for determining whether Evil Limiter is compatible with your equipment and other software installed on your equipment. You are also solely responsible for the protection of your equipment and backup of your data, and the provider will not be liable for any damages you may suffer in connection with using, modifying, or distributing this software.

License

Copyright (c) 2019 by bitbrute. Some rights reserved.
Evil Limiter is licensed under the MIT License as stated in the LICENSE file.

Frequently asked questions

Is evillimiter free to use?

evillimiter is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does evillimiter do?

Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access

What is evillimiter written in?

evillimiter is primarily written in Python. Its source is publicly available at https://github.com/bitbrute/evillimiter, and it has 2,024 GitHub stars.