Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
My results in bestguess.log are backward. The instances I have matching are destination port 53 and source port 44818. This is flagging ENIP/Rockwell traffic for some reason where this is actually DNS information in the log itself.
My results in bestguess.log are backward. The instances I have matching are destination port 53 and source port 44818. This is flagging ENIP/Rockwell traffic for some reason where this is actually DNS information in the log itself.
Log included below:
Malcolm Version: Malcolm v24.03.1