cisagov / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://cisagov.github.io/Malcolm/
Other
1.97k stars 331 forks source link

investigate Strelka for file scanning #485

Open mmguero opened 2 weeks ago

mmguero commented 2 weeks ago

@mmguero cloned issue idaholab/Malcolm#23 on 2020-09-09:

From Malcolm created by mmguero: cisagov/Malcolm#149

My zeekcarve*.py scripts in shared/bin aren't bad, but I just became aware of Strelka which might scale better for a file scanning solution.