# cisagov/Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

Repository: https://github.com/cisagov/Malcolm
Canonical: https://ross.abutalabs.com/products/malcolm
Homepage: https://cisagov.github.io/Malcolm/
Language: Python
License: NOASSERTION
License Family: other
Topics: network-security, pcap, security, arkime, cybersecurity, infosec, network-traffic-analysis, networksecurity, opensearch, opensearch-dashboards, suricata, zeek, networktrafficanalysis
Last push: 2026-08-25T22:26:12+00:00

## Health v2 (maintenance only)
Score: 99/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 99, longevity 100
- inputs: {"age_days": 2669, "days_push": 8, "days_rel": 8, "gap_med": 21.0, "n_releases_24m": 31}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2497, forks 442 (observed 2026-08-28T04:06:56.775945+00:00)

## What it is
Malcolm is a containerized network traffic analysis tool suite that ingests full packet capture (PCAP) files, Zeek logs, and Suricata alerts, normalizing and correlating them for analysis. It provides visualization through OpenSearch Dashboards and session exploration through Arkime, deployable on Linux servers or laptops for SOC monitoring and incident response.

## Use cases
- analyze pcap files for network security incidents
- deploy a network security monitoring platform for a SOC
- hunt threats in zeek logs and suricata alerts
- investigate suspicious network sessions during incident response
- monitor industrial control system network protocols
- visualize network protocol traffic with prebuilt dashboards
- self-hosted alternative to paid network traffic analysis tools

## When to choose
- you need an easily deployable, container-based NSM platform combining Zeek, Suricata, and Arkime
- you want prebuilt dashboards and session search over full packet capture data
- you need visibility into industrial control system (ICS) protocols
- you want a free open-source alternative to commercial network analysis solutions

## When to avoid
- you need lightweight host-based intrusion detection rather than network traffic analysis
- you lack the hardware resources to run a multi-container cluster
- you need real-time inline blocking rather than passive capture and analysis
- you want a simple single-binary packet parser instead of a full analysis suite

## Facets
- artifact type: application
- maturity: active
- function: monitoring, search-engine, data-visualization, security, analytics
- domain: security, networking, developer-tools
- platform: self-hosted
- tags: network-traffic-analysis, pcap-analysis, zeek, suricata, arkime, opensearch, network-security-monitoring, ids, full-packet-capture, incident-response, ics-protocols, linux, docker, macos, web-server

## Member repositories
- cisagov/Malcolm (main) score 99

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:56.775945+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:27:04.207842+00:00, confidence not recorded.
  - readme: https://github.com/cisagov/Malcolm (fetched 2026-08-28T04:06:56.775945+00:00, sha 62dfc0628eac)
  - homepage: https://cisagov.github.io/Malcolm/ (fetched 2026-08-29T10:09:35.123514+00:00, sha 5d52f3b4ab80)
- Data as of 2026-08-30T08:39:29.467469+00:00.
