Malcolm

Traffic analyzer

A powerful tool suite for analyzing and visualizing network traffic data

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

GitHub

368 stars
20 watching
59 forks
Language: Python
last commit: almost 2 years ago
Linked from 2 awesome lists

arkimecybersecurityinfosecnetwork-securitynetwork-traffic-analysisnetworksecuritynetworktrafficanalysisopensearchopensearch-dashboardspcapsecuritysuricatazeek

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
cisagov/malcolmA network traffic analysis tool suite that accepts various data formats and provides visualization and incident response capabilities.2,001
tomchop/malcomAnalyzes network traffic to detect malware communication and behavior1,158
ch3k1/squidmagicAnalyzes web-based network traffic to detect malicious command and control servers using Squid proxy server and Spamhaus78
michoo/pciAnalyzes network traffic to investigate packet interactions and visualize connections on a graph-based platform.90
activecm/ritaA framework for detecting malicious communication patterns in network traffic by analyzing Zeek logs.215
shmohammadi86/netdecodeA tool to decode and analyze network traffic patterns0
cisco/mercuryA tool for analyzing and extracting metadata from network packets447
srinivas11789/pcapxrayA tool to visualize network traffic and extract information from packet captures1,700
phaethon/kameneA tool for crafting and analyzing network packets and pcap files to support security research and testing.869
sunwxg/golibwiresharkA Go-based tool for decoding and analyzing network capture files using the libwireshark library.29
linklayer/reversegearAutomated toolset for analyzing and decoding automotive network traffic logs46
certego/pcapmonkeyAn analysis tool for packet capture files using Suricata and Zeek145
benjeems/packetstriderAnalyzes network traffic from SSH connections to detect potential security threats and reverse sessions.254
thewhiteh4t/thewhiteh4tA toolkit for analyzing and manipulating network traffic patterns to identify potential security threats93
marty90/netlyticsA framework for performing advanced analytics on network logs using Hadoop and Apache Spark9