Theme
FeaturesHow It WorksPricingBlogSign In to Dashboard →Download Mac App
← All posts
Ports & Processes

How to Inspect Active AWS EC2 Sessions and SSH Tunnels on Your Mac

The Silo Team · 6 min read · September 21, 2026

The Problem: You Have No Idea What's Tunneled

After a day of debugging, your Mac might be running 3 SSH tunnels to production databases, 2 AWS SSM sessions, and a Cloudflare tunnel — with no easy way to see them all. Standard tools like netstat and lsof show socket-level data but don't map tunnels to their remote endpoints.

How MacPilot Discovers Tunnels

MacPilot uses Darwin's KERN_PROCARGS2 sysctl to read the full command-line arguments of every running process. This allows it to:

  • Parse SSH tunnel flags: -L (local forward), -R (remote forward), -D (SOCKS5 dynamic proxy)
  • Identify AWS EC2 instances: by matching SSH connections to *.compute.amazonaws.com or ec2-* hostnames
  • Detect AWS SSM sessions: by finding session-manager-plugin processes
  • Find Cloudflare tunnels: by detecting cloudflared processes
  • Flag ngrok: by detecting ngrok agent processes and their forwarded ports

Manual Inspection Commands

# Find all SSH tunnel processes
ps aux | grep 'ssh.*-[LRD]'

# Find AWS SSM sessions
ps aux | grep 'session-manager-plugin'

# Find cloudflared processes
ps aux | grep cloudflared

# Find ngrok tunnels
ps aux | grep ngrok

Security Implications

Active tunnels represent security-relevant context. An SSH -R (remote forward) makes a local service reachable from a remote server — effectively punching a hole in your firewall. MacPilot's Cloud Tunnel panel highlights these with visual risk indicators and lets you terminate them with a single click.

See it on your own Mac.

Download Silo and find out where your space is going.

Download Silo →

Keep reading

Silo Support Desk

Help & Feedback

Send a message to our engineering team. We typically respond within 12 hours.

Direct email support: sparoconnect@gmail.com