Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
-
Updated
Nov 18, 2024 - Python
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
Cyber Defence Monitoring Course Suite :: Suricata, Arkime (and others in the past)
DShield Sensor Log Collection with ELK
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
Splunk add-on to perform basic searches against the back end of Arkime using the Elasticsearch REST API.
This project aims to simplify the process of setting up Arkime, which can be daunting for brand-neww network analysts. Unlike the traditional Arkime build, this repository provides a streamlined approach using Docker Compose and environment variables.
Add a description, image, and links to the arkime topic page so that developers can more easily learn about it.
To associate your repository with the arkime topic, visit your repo's landing page and select "manage topics."