Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
-
Updated
Apr 2, 2025 - Python
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
Cyber Defence Monitoring Course Suite :: Suricata, Arkime (and others in the past)
DShield Sensor Log Collection with ELK
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
This project aims to simplify the process of setting up Arkime, which can be daunting for brand-neww network analysts. Unlike the traditional Arkime build, this repository provides a streamlined approach using Docker Compose and environment variables.
Splunk add-on to perform basic searches against the back end of Arkime using the Elasticsearch REST API.
Add a description, image, and links to the arkime topic page so that developers can more easily learn about it.
To associate your repository with the arkime topic, visit your repo's landing page and select "manage topics."