A tool to monitor, analyze and limit the bandwidth (upload/download) of devices on your local network without physical or administrative access.
evillimiter-ng employs ARP spoofing and traffic shaping to throttle the bandwidth of hosts on the network.
New in version 3.0: Use the code as a library instead of a CLI
- Linux distribution with nftables
- Python 3.10 or greater
Possibly missing python packages will be installed during the installation process.
pip install evillimiter-ngUsing the AUR, the package can be installed manually:
git clone https://aur.archlinux.org/evillimiter-ng.git
cd evillimiter-ng
makepkg -siOr using AUR helpers:
# Using KPA (https://github.com/KevinCrrl/kpa)
kpa Ins evillimiter-ng
# Or using yay (https://github.com/Jguer/yay)
yay -S evillimiter-ngLearn how to use the library API for your own projects, write less code, take advantage of the architecture based on lists of IPs with assigned IDs, and find more uses for the code beyond the terminal program: Library docs
After installation, you can start using the tool with the following basic workflow.
- Start the program and specify your network interface:
evillimiter-ng -i wlan0- Scan the network for connected hosts:
scan- Limit bandwidth of a device (example: device ID 3 to 200kbit):
limit 3 200kbit# Scan the network, list hosts, block everyone for 20 seconds, and then restore connection.
echo "scan && hosts && block all && sleep 20 && free all && exit" | evillimiter-ng# Scan the network, and save the results in a JSON file encoded in base64
scan && export-json my_network.jsonWith it, you can restore these results without a new scan in a future session:
import-json my_network.json🛑 CRITICAL SECURITY WARNING
Base64 is NOT encryption (like PGP). It only obfuscates sensitive data (local IPs, MAC addresses) so they aren't visible to the naked eye. Any user or program can easily decode this file.
- Permissions: The file is read-proctected and write-protected (root only) to prevent corruption.
- Risk: Even if a malicious user obtains root access, they cannot decrypt what was never encrypted, but they can read, corrupt or destroy the information. Do not rely on this file for confidentiality.
| Argument | Explanation |
|---|---|
-h |
Displays help message listing all command-line arguments |
-s |
Enables a shell mode for typing commands and hides banners and flashy elements |
-i [Interface Name] |
Specifies network interface (resolved if not specified) |
-g [Gateway IP Address] |
Specifies gateway IP address (resolved if not specified) |
-m [Gateway MAC Address] |
Specifies gateway MAC address (resolved if not specified) |
-n [Netmask Address] |
Specifies netmask (resolved if not specified) |
You can use the command -h to see the general help menu, also, each command has a submenu generated by argparse, you can view the help for these by typing:
>>> <COMMAND_NAME> -hFor example:
>>> scan -h
usage: scan [-h] [-r RANGE] [-i INTENSITY]
options:
-h, --help show this help message and exit
-r, --range RANGE
-i, --intensity INTENSITY
# Another example:
>>> watch --help
usage: watch [-h] {add,remove,set} ...
positional arguments:
{add,remove,set}
add Adds host to the reconnection watchlist. e.g.: watch add 3,4
remove Removes host from the reconnection watchlist. e.g.: watch remove all
set Changes reconnect watch settings. e.g.: watch set interval 120 watch set intensity 1
options:
-h, --help show this help message and exit
This table shows all the available commands:
| Command | Explanation |
|---|---|
scan (--range [IP Range]) (--intensity [(1,2,3)]) |
Scans your network for online hosts. One of the first things to do after start.--range lets you specify a custom IP range.--intensity lets you specify the scan intensity / speed (1 = quick, 2 = normal (standard), 3 = intense).Example: scan --range 192.168.178.1-192.168.178.40 --intensity 1 or just scan. |
hosts |
Displays all scanned hosts and basic information. |
limit [ID1,ID2,...] [Rate] (--upload) (--download) |
Limits bandwidth of host(s) associated with specified ID. |
block [ID1,ID2,...] (--upload) (--download) |
Blocks internet connection of host(s). |
free [ID1,ID2,...] |
Removes bandwidth restrictions. |
add [IP] (--mac [MAC]) |
Adds custom host manually. |
monitor (--with-id [ID1,ID2,...]) (--interval [time in ms]) |
Monitor bandwidth usage of host(s). |
analyze [ID1,ID2,...] (--duration [time in s]) |
Analyze traffic usage. |
watch |
Shows current watch status. |
watch add [ID1,ID2,...] |
Adds host(s) to watchlist. |
watch remove [ID1,ID2,...] |
Removes host(s) from watchlist. |
watch set [Attribute] [Value] |
Changes watch settings. |
clear |
Clears terminal window. |
exit |
Quits the application. |
sleep |
Waits for seconds. |
-h, --help |
Displays command help. |
import-json, export-json [JSON_FILE_PATH] |
Import/Export a JSON file containing IP addresses and MAC addresses encoded in base64. |
- Limits IPv4 connections only, since ARP spoofing requires ARP packets which exist only in IPv4 networks.
Please read the full legal disclaimer here:
Copyright (c) 2026 by KevinCrrl.
Licensed under the GPL-2.0-only License.
For a detailed list of original authors, dependencies, and their respective licenses, see the CREDITS file.
