Malcolm

Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed

About

Malcolm is a network traffic analysis suite for security monitoring. It accepts PCAP files, Zeek logs and Suricata alerts through a browser, or live traffic sent by lightweight forwarders. Malcolm adds GeoIP, MAC-vendor, asset-inventory and JA4 fingerprinting information to network sessions. Analysts can explore results in OpenSearch Dashboards using prebuilt dashboards, or search and identify sessions with Arkime. The software runs in containers deployed with Docker, Podman or Kubernetes, and is also available as a standalone Debian-based installer ISO. Its web interfaces support browser access from analyst workstations or SOC displays. The project documents host configurations for Linux, macOS and Windows, and authentication options including local accounts, LDAP, TLS certificates and Keycloak. Malcolm provides a REST API and forwards requests to APIs for Logstash, OpenSearch, NetBox and Arkime. It is free and released under the Apache License 2.0. Rootless Podman cannot capture local network-interface traffic, though Malcolm can receive forwarded metadata from a network sensor appliance.

Who it is for

Malcolm suits security operations teams, smaller networks and home environments that need network traffic monitoring. It also targets field incident-response work and supports live capture or uploaded data.

What is good

  • Accepts PCAP, Zeek logs and Suricata alerts.
  • Enriches sessions with GeoIP and JA4 lookups.
  • Includes OpenSearch Dashboards and Arkime interfaces.
  • Deploys with Docker, Podman or Kubernetes.
  • Free under Apache License 2.0.

What to know first

  • Rootless Podman cannot capture local interface traffic.
  • The installer formats non-removable storage without warning.

Verdict

Malcolm combines multiple traffic inputs, enrichment and analysis interfaces in a container-based deployment. Check the rootless Podman capture limitation and the installer’s storage behavior before choosing a deployment path.

Compared on network packet analyzer software

Free plan
Yesidaholab.github.io
Live capture
Yesidaholab.github.io
Command-line tool
Yesidaholab.github.io
Operating systems
Linux, macOS, Windowsidaholab.github.io
Capture file formats
PCAPidaholab.github.io
Protocol dissectors
Yesidaholab.github.io

Facts

Purpose
Malcolm is an easily deployable network traffic analysis tool suite for network security monitoring.idaholab.github.io · 30 Sept 2026
Input data
It accepts PCAP files, Zeek logs and Suricata alerts, which can be uploaded through a browser interface or captured live and forwarded by lightweight forwarders.github.com · 30 Sept 2026
Traffic enrichment
Malcolm enriches network session data with GeoIP, MAC-vendor, asset-inventory and JA4 fingerprinting lookups.idaholab.github.io · 30 Sept 2026
Analysis interfaces
It provides OpenSearch Dashboards with prebuilt dashboards and Arkime for searching and identifying network sessions.idaholab.github.io · 30 Sept 2026
Deployment model
Malcolm runs as a cluster of containers and can also be packaged as a standalone Debian-based installer ISO.idaholab.github.io · 30 Sept 2026
Supported hosts
Official host-configuration documentation is provided for Linux, macOS and Windows.idaholab.github.io · 30 Sept 2026
Security
Communications from the user interface and remote log forwarders use industry-standard encryption protocols.github.com · 30 Sept 2026
Authentication
The documentation includes local accounts, LDAP authentication, TLS certificates and Keycloak-based authentication and roles.idaholab.github.io · 30 Sept 2026
Integrations
Malcolm uses Arkime, OpenSearch, Logstash, Filebeat, Zeek, Suricata, Strelka, YARA, Capa, ClamAV, MISP, TAXII, NetBox, PostgreSQL, Valkey and Keycloak among other components.idaholab.github.io · 30 Sept 2026
API
Malcolm provides a REST API and forwards requests to Logstash, OpenSearch, NetBox and Arkime APIs.idaholab.github.io · 30 Sept 2026
License
Malcolm source code is released under the Apache License, Version 2.0.idaholab.github.io · 30 Sept 2026
Target users
The project describes use in security operations centers, smaller networks, home environments and field incident-response engagements.idaholab.github.io · 30 Sept 2026
Podman limitation
With rootless Podman, Malcolm cannot capture traffic on local network interfaces, although it can accept metadata forwarded from a network sensor appliance.idaholab.github.io · 30 Sept 2026
Installer warning
The installer has no partitioning confirmations and will partition and format all non-removable storage media without warning.idaholab.github.io · 30 Sept 2026
Support contact
The project lists [email protected] as the author contact address.github.com · 30 Sept 2026
Data enrichment
Malcolm adds GeoIP, hardware-manufacturer, asset-inventory and JA4 fingerprinting enrichments.idaholab.github.io · 1 Oct 2026
Web access
Its analysis interfaces are accessed through a web browser from analyst workstations or SOC displays.idaholab.github.io · 1 Oct 2026
Deployment
Malcolm runs as isolated software containers and can be deployed with Docker, Podman or Kubernetes, including AWS Kubernetes deployments.idaholab.github.io · 1 Oct 2026
Supply-chain security
Official Malcolm container images are automatically scanned with Trivy for vulnerabilities and misconfigurations.idaholab.github.io · 1 Oct 2026
Hardening
The ISO-installed aggregator environment uses hardening scripts targeting CIS recommendations and adapted DISA STIG checks.idaholab.github.io · 1 Oct 2026
Use cases
The project targets long-term SOC deployments, incident-response engagements, smaller networks and home use.idaholab.github.io · 1 Oct 2026
ICS focus
Its creators are developing additional parsers for protocols used in industrial-control-system environments.idaholab.github.io · 1 Oct 2026
Deployment limitation
Rootless Podman cannot capture traffic on local network interfaces, although it can accept metadata forwarded from a network sensor appliance.idaholab.github.io · 1 Oct 2026
Support and training
The Malcolm program team provides contact through [email protected] and lists general and technical virtual orientations.inl.gov · 1 Oct 2026

Best Malcolm alternatives

See all 12