Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
After seeing the ZeekWeek 2021 presentation on packet capture with DPDK, It would be interesting to investigate this as an alternative to afpacket for packet capture on the hedgehog.
After seeing the ZeekWeek 2021 presentation on packet capture with DPDK, It would be interesting to investigate this as an alternative to afpacket for packet capture on the hedgehog.
https://github.com/esnet/dpdk-plugin