Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
I thought I had this worked out, but apparently not. There are some false positives that need to be handled in the AIDE configuration (Malcolm, Hedgehog) in the ISO installed versions of these tools.
@mmguero cloned issue idaholab/Malcolm#106 on 2022-07-13: