Network Analyzers

Malcolm – network traffic analysis suite

Malcolm is a network traffic analysis suite designed for network security monitoring, threat hunting and incident response.

It ingests full packet capture (PCAP) files, Zeek logs and Suricata alerts, then normalizes, enriches and correlates the data for investigation.

Analysts can explore network activity through OpenSearch Dashboards and Arkime. Malcolm supports offline artifact analysis and live traffic capture, and can be deployed as containerized services on a workstation, server or Kubernetes cluster. It places particular emphasis on visibility into industrial control system protocols.

This is free and open source software.

Key Features

  • Processes PCAP files, Zeek logs and Suricata alerts.
  • Supports browser-based artifact uploads and live network traffic capture.
  • Accepts logs securely forwarded from remote network sensors.
  • Normalizes, enriches and correlates network session data.
  • Provides GeoIP, MAC address manufacturer and asset inventory enrichment.
  • Supports JA4 network traffic fingerprinting.
  • Includes OpenSearch Dashboards with numerous prebuilt visualizations.
  • Uses Arkime for searching, examining and correlating network sessions.
  • Offers anomaly detection, alerting, reporting and event severity scoring.
  • Supports automatic file extraction and scanning.
  • Integrates threat intelligence through STIX, TAXII and MISP.
  • Uses NetBox for asset inventory and network interaction analysis.
  • Provides additional visibility into industrial control system protocols.
  • Supports local accounts, LDAP, Keycloak and role-based access control.
  • Can run with Docker or Podman and supports Kubernetes deployments.

Website: github.com/cisagov/Malcolm
Support:
Developer: Idaho National Laboratory
License: Apache License 2.0

Malcolm is written in Python. Learn Python with our recommended free books and free tutorials.


Related Software

Network Analyzers
WiresharkNetwork protocol analyzer with a rich and powerful feature set
EttercapComprehensive suite for man in the middle attacks
KismetWireless network and device detector, sniffer, wardriving tool
IPTraf-ngFeature-laden network statistic monitoring tool
netsniff-ngSwiss army knife for daily Linux network plumbing
KyanosNetworking analysis tool using eBPF
EtherApeGraphical network monitor
darkstatCaptures network traffic, calculates usage statistics, and serves reports
justnifferNetwork TCP packet sniffer with reliable TCP flow rebuilding
tcpflowTCP/IP packet demultiplexer
tcpdumpPowerful and hugely respected command-line packet analyzer
sniffgluePacket sniffer written in Rust
sniffer Alternative network traffic sniffer
dsniffCollection of tools for network auditing and penetration testing
ngrepgrep applied to the network layer
Network MonitorRreal-time network connection monitoring tool
sniffitCORBA based sniffer system with ncurses interactive mode
JomonNetwork forensics and sniffer tool

Read our verdict in the software roundup.


Best Free and Open Source Software Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.

This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk.

You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more.

Discovered a useful open source Linux program that we haven’t covered yet? Let us know by completing this form.
Subscribe

Please read our Comment Policy before commenting.

Notify of
guest
0 Comments
Oldest
Newest Most Voted