idaholab / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://idaholab.github.io/Malcolm/
Other
353 stars 58 forks source link

"policy manager" for Malcolm and Hedgehog Linux (meta-issue) #477

Open mmguero opened 4 months ago

mmguero commented 4 months ago

This is needs to be broken down into multiple sub-tasks, but we'll keep the high-level ideas here.

Users have requested a way to "manage sensors and rules" from Malcolm. What this has entailed in discussions is:

I'm going to create a "policy" label to assign to issues associated with this one.

mmguero commented 1 month ago

see also #430 which may be related, as well as #221