Malcolm is a powerful suite of network analytics tools designed with network security in mind.
Although all of the open source tools that make up Malcolm are already available and in general use, it provides an interface framework that makes it greater than the sum of its parts. While there are many other solutions for network analysis, for all distributions Linux like Security Onion to licensed products like Splunk Enterprise Security, Malcolm's creators feel optimistic that its powerful combination of tools will fill a gap in the network security space that will make network traffic analysis accessible to many in both the public and private sector as well as individual users.
Specifications
- Easy to useMalcolm receives packages (PCAP) and archives recording Zeek (formerly Bro). These objects can be uploaded through a simple browser-based interface or recorded live and forwarded to. In both cases, the data is automatically normalized, enriched and correlated for analysis.
- Powerful network analyzer– Visibility into network communications is provided through two intuitive interfaces: Kibana, a flexible data visualization plugin with dozens of predefined tables control which provide a quick overview of network protocols. And Moloch, a powerful tool for finding and tracing network sessions that include suspicious security events.
- Improved growth– Malcolm acts as a Docker cluster, where it serves a special system function. This Docker-based development model, combined with a few simple scripts to set up and management makes Malcolm suitable for fast deployment across multiple platforms and applications, whether it is long-term deployment on a Linux server, a Security Operations Center (SOC), or responding to Macbook events for individual use.
- Secure in communications All communications with Malcolm, both from the user interface and from remote logging forwarders, are secured with industry standard encryption protocols.
- Open source program Malcolm is made up of many well-known open source tools, making it an attractive alternative to security solutions that require paid licenses.
- Visibility of the control systemWhile Malcolm is ideal for general purpose network traffic analysis, its creators see a particular need in the community for tools that provide information about protocols used in industrial control systems (ICS) environments. The continued development of Malcolm aims to provide additional analyzers for common ICS protocols.
In short, Malcolm provides an easy-to-use suite of network analysis tools for complete packet collection (PCAP files) and Zeek logs. While internet access is required to create it, it is not required when running it.
Application snapshots
You will find the program installation guide as well as user functions here