Ross ROSS = Recommend OSS · open-source software intelligence for agents

cisagov/Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts. observed · 2026-08-28

github.com/cisagov/Malcolm · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

99/100

  • Activity 99
  • Release rhythm 99
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 21.0
  • age_days: 2669
  • days_rel: 8
  • days_push: 8
  • n_releases_24m: 31

Full methodology

Adoption not part of the score

2497 stars · 442 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Malcolm is a containerized network traffic analysis tool suite that ingests full packet capture (PCAP) files, Zeek logs, and Suricata alerts, normalizing and correlating them for analysis. It provides visualization through OpenSearch Dashboards and session exploration through Arkime, deployable on Linux servers or laptops for SOC monitoring and incident response.

Use cases

  • analyze pcap files for network security incidents
  • deploy a network security monitoring platform for a SOC
  • hunt threats in zeek logs and suricata alerts
  • investigate suspicious network sessions during incident response
  • monitor industrial control system network protocols
  • visualize network protocol traffic with prebuilt dashboards
  • self-hosted alternative to paid network traffic analysis tools

When to choose

  • you need an easily deployable, container-based NSM platform combining Zeek, Suricata, and Arkime
  • you want prebuilt dashboards and session search over full packet capture data
  • you need visibility into industrial control system (ICS) protocols
  • you want a free open-source alternative to commercial network analysis solutions

When to avoid

  • you need lightweight host-based intrusion detection rather than network traffic analysis
  • you lack the hardware resources to run a multi-container cluster
  • you need real-time inline blocking rather than passive capture and analysis
  • you want a simple single-binary packet parser instead of a full analysis suite

Facets

application · maturity active

monitoring search-engine data-visualization security analytics security networking developer-tools self-hosted network-traffic-analysis pcap-analysis zeek suricata arkime opensearch network-security-monitoring ids full-packet-capture incident-response ics-protocols linux docker macos web-server

2 sources

Member repositories

RepositoryRoleHealth v2
cisagov/Malcolmmain99

For agents

markdown · JSON · MCP: product_card(name="cisagov/Malcolm")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem