idaholab / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://idaholab.github.io/Malcolm/
Other
327 stars 53 forks source link

investigate integrating sandialabs/gait Zeek plugin #418

Closed mmguero closed 4 months ago

mmguero commented 4 months ago

A colleague sent me this link, we should see if it would make a good fit for Malcolm

sandialabs/gait

piercema commented 4 months ago

A review of the tool shows that it is relatively new. It provides a few additional metrics focused on profiling endpoints and proxies. Although it can add interesting data this data isn't central to Malcolm's goals. Due to limited development time, we will not be pursuing integrating this but users are welcome to integrate this plugin independently.