idaholab / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://idaholab.github.io/Malcolm/
Other
327 stars 53 forks source link

using threat intelligence feeds with Malcolm #424

Closed mmguero closed 4 months ago

mmguero commented 4 months ago

For what topic would you like to see training developed? Show, using some sample feeds, setting up and using threat intelligence feeds with Zeek.

What format would be best suited for this training? A video

Is there existing Malcolm documentation that could be improved by including this topic?

Zeek Intelligence Framework

mmguero commented 4 months ago

dupe of #369