How to Inspect Active AWS EC2 Sessions and SSH Tunnels on Your Mac
The Silo Team · 6 min read · September 21, 2026
The Problem: You Have No Idea What's Tunneled
After a day of debugging, your Mac might be running 3 SSH tunnels to production databases, 2 AWS SSM sessions, and a Cloudflare tunnel — with no easy way to see them all. Standard tools like netstat and lsof show socket-level data but don't map tunnels to their remote endpoints.
How MacPilot Discovers Tunnels
MacPilot uses Darwin's KERN_PROCARGS2 sysctl to read the full command-line arguments of every running process. This allows it to:
- Parse SSH tunnel flags:
-L(local forward),-R(remote forward),-D(SOCKS5 dynamic proxy) - Identify AWS EC2 instances: by matching SSH connections to
*.compute.amazonaws.comorec2-*hostnames - Detect AWS SSM sessions: by finding
session-manager-pluginprocesses - Find Cloudflare tunnels: by detecting
cloudflaredprocesses - Flag ngrok: by detecting ngrok agent processes and their forwarded ports
Manual Inspection Commands
# Find all SSH tunnel processes
ps aux | grep 'ssh.*-[LRD]'
# Find AWS SSM sessions
ps aux | grep 'session-manager-plugin'
# Find cloudflared processes
ps aux | grep cloudflared
# Find ngrok tunnels
ps aux | grep ngrok
Security Implications
Active tunnels represent security-relevant context. An SSH -R (remote forward) makes a local service reachable from a remote server — effectively punching a hole in your firewall. MacPilot's Cloud Tunnel panel highlights these with visual risk indicators and lets you terminate them with a single click.