cisagov/Malcolm
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts. observed · 2026-08-28
Health v2 · maintenance only
99/100
- Activity 99
- Release rhythm 99
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 21.0
- age_days: 2669
- days_rel: 8
- days_push: 8
- n_releases_24m: 31
Adoption not part of the score
2497 stars · 442 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Malcolm is a containerized network traffic analysis tool suite that ingests full packet capture (PCAP) files, Zeek logs, and Suricata alerts, normalizing and correlating them for analysis. It provides visualization through OpenSearch Dashboards and session exploration through Arkime, deployable on Linux servers or laptops for SOC monitoring and incident response.
Use cases
- analyze pcap files for network security incidents
- deploy a network security monitoring platform for a SOC
- hunt threats in zeek logs and suricata alerts
- investigate suspicious network sessions during incident response
- monitor industrial control system network protocols
- visualize network protocol traffic with prebuilt dashboards
- self-hosted alternative to paid network traffic analysis tools
When to choose
- you need an easily deployable, container-based NSM platform combining Zeek, Suricata, and Arkime
- you want prebuilt dashboards and session search over full packet capture data
- you need visibility into industrial control system (ICS) protocols
- you want a free open-source alternative to commercial network analysis solutions
When to avoid
- you need lightweight host-based intrusion detection rather than network traffic analysis
- you lack the hardware resources to run a multi-container cluster
- you need real-time inline blocking rather than passive capture and analysis
- you want a simple single-binary packet parser instead of a full analysis suite
Facets
application · maturity active
monitoring search-engine data-visualization security analytics security networking developer-tools self-hosted network-traffic-analysis pcap-analysis zeek suricata arkime opensearch network-security-monitoring ids full-packet-capture incident-response ics-protocols linux docker macos web-server
2 sources
- readme: https://github.com/cisagov/Malcolm · fetched 2026-08-28 · 62dfc0628eac
- homepage: https://cisagov.github.io/Malcolm/ · fetched 2026-08-29 · 5d52f3b4ab80
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| cisagov/Malcolm | main | 99 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem