Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
review and fix capabilities granted to containers (idaholab/Malcolm#282)
change URL for downloading manuf list to new wireshark.org URL / wireshark no longer publishes raw manuf (OUI) list (idaholab/Malcolm#230 and idaholab/Malcolm#306)
directory hierarchies not being created as Kubernetes configmap correctly (idaholab/Malcolm#308)
rsyslog no longer in Debian bookworm (idaholab/Malcolm#309)
Malcolm v23.12.0 is a minor release with a few updates and bug fixes
https://github.com/cisagov/Malcolm/compare/v23.12.0...v23.12.1
install.py
offer to pull the docker images (idaholab/Malcolm#310)config.ini
withconfig.orig.ini
ifconfig.ini
doesn't already exist (idaholab/Malcolm#311)capture
to listen on the interface directly rather than post-processing PCAPs (idaholab/Malcolm#281)SURICATA_DISABLE_ICS_ALL
environment variable to disable OT/ICS analysis in SuricataZEEK_INTEL_REFRESH_THREADS
to allow setting the number of threads for intel feed pullshedgehog
vs.malcolm
profiles) and generally improved documentation of live capture options/mapi/opensearch/
,/mapi/logstash/
and/mapi/netbox/
from the Malcolm API endpoint to their respective component APIs