Malcolm

A self-hosted network traffic analysis suite that turns PCAP files, Zeek logs and Suricata alerts into searchable dashboards.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About Malcolm

Malcolm collects full packet capture files, Zeek logs and Suricata alerts and loads them into a searchable stack of tools, so an analyst can browse sessions, filter traffic and investigate alerts from a web interface instead of working through raw captures.

It is published by the US Cybersecurity and Infrastructure Security Agency (CISA) and runs as a set of containers. The repository includes Docker and Kubernetes configurations, an installable ISO, Arkime, OpenSearch dashboards, NetBox integration, file scanning, and a Hedgehog sensor build for Raspberry Pi. It suits security teams and network defenders who need to analyse captured traffic on their own hardware.

Strengths

  • Brings PCAP, Zeek and Suricata data together in one searchable interface
  • Deployable with Docker, Kubernetes or an installable ISO
  • Includes Arkime, OpenSearch dashboards and NetBox integration
  • Optional Hedgehog sensor build for Raspberry Pi capture

Limitations

  • A large multi-container stack that needs substantial server resources
  • Aimed at trained analysts rather than casual home users

Details

Pricing
FreeFree to use; the source is published on GitHub by CISA.
License
Open source, license not stated
Developer
CISA
Platforms
Linux, Self-hosted
How it runs
Self-hosted
Works offline
Yes
Best suited for
Security teams analysing captured network traffic on their own infrastructure
Last verified
Added
Provenance
Facts checked against the developer's own pages and store listings, 1 sources on file.

Alternatives to Malcolm

Compare all

Software that can replace Malcolm for an important use case, and what changes if you switch.

  • Security Onion

    A free Linux distribution for network security monitoring, packet capture, detection and threat hunting.

    Security Onion installs as a full Linux distribution from one ISO with packet capture, detection rules and threat hunting, though some parts like Onion AI go through sales.

  • Arkime

    Store and search captured network traffic through a web interface.

    Arkime covers only the packet storage and session search part of the stack, indexing sessions and keeping PCAP data through a web interface without Zeek or Suricata dashboards.

Malcolm as an alternative

Listings that name Malcolm as an alternative.

  • NetworkMiner

    Network forensics tool that extracts files and credentials from captures.

    Malcolm is a self-hosted suite that combines PCAP, Zeek and Suricata data into searchable dashboards, but it is a large multi-container stack needing substantial resources.

  • ntopng

    Web-based network traffic probe that shows real-time and historical flows by host, protocol and application.

    Malcolm is free and open source, analysing PCAP files, Zeek logs and Suricata alerts in searchable dashboards, but it is a large multi-container stack needing substantial server resources.

  • RITA

    A network traffic analysis framework that detects command and control communication such as beaconing.

    Malcolm is a self-hosted multi-container suite turning PCAP files, Zeek logs and Suricata alerts into searchable dashboards, needing more server resources than RITA.

  • Zeek

    Network analysis framework that turns traffic into high-level activity logs.

    Malcolm packages Zeek and Suricata data with searchable dashboards in a large multi-container stack that needs substantial server resources.

Similar software

Related functionality, not necessarily a direct replacement.

Report a wrong fact or a dead link on this listing