cisagov / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://cisagov.github.io/Malcolm/
Other
1.97k stars 331 forks source link

Capturing Live Network Traffic for Analysis #444

Open mmguero opened 2 weeks ago

mmguero commented 2 weeks ago

@mmguero cloned issue idaholab/Malcolm#353 on 2024-01-15:

For what topic would you like to see training developed?

Describe the ways Malcolm can analyze live network traffic: via a sensor device (Hedgehog Linux) or by monitoring local network interfaces.

What format would be best suited for this training?

A video

Is there existing Malcolm documentation that could be improved by including this topic?

Live analysis

mmguero commented 2 weeks ago

@mmguero commented on 2024-02-26:

Some notes for consideration:

  • time zones / time filters
  • sensors vs. Malcolm time in sync
  • differences in live vs. PCAP-uploaded traffic