idaholab / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://idaholab.github.io/Malcolm/
Other
357 stars 59 forks source link

update ethernet/IP and CIP to account for new packet correlation ID #558

Closed mmguero closed 1 month ago

mmguero commented 1 month ago

cisagov/icsnpp-enip#30 adds a "packet correlation ID" field to help correlate between enip and cip logs. This issue tracks the changes needed for Malcolm to do this.

mmguero commented 1 month ago

Done

Image