Malcolm

APIyesOSS—FREEyesDOCS4/5
MA7.3#1 of 20
outWeboutWindowsoutMacoutLinux—Android—iOS

Ranked in Network Packet Capture Software ·Free plan

About

Malcolm is a free, self-hosted suite for network traffic analysis and security monitoring. It accepts PCAP files, Zeek logs and Suricata alerts through a browser, and can also process live captures sent by lightweight sensors. OpenSearch Dashboards supports visualizations, while Arkime helps locate and identify network sessions. The suite enriches session data with GeoIP, hardware manufacturer lookups, asset inventory mappings and JA4 fingerprinting. Its documented components include Zeek, Suricata, Arkime, OpenSearch, NetBox, MISP, TAXII and Google and Mandiant threat intelligence sources. It analyzes documented protocols including DNS, HTTP, Modbus and BACnet. Malcolm runs in Docker or Podman containers, with Kubernetes deployment described for on-premises use or AWS. A dedicated server requires at least 8 CPU cores and 24 GB of RAM; the developers recommend 16 or more cores and 32 GB or more RAM for an optimal experience. It requires authentication and supports local TLS-encrypted basic authentication, LDAP and Keycloak.

Who it is for

Malcolm suits network security teams that need to analyze offline traces or live traffic and can operate self-hosted container deployments. Its stated hardware requirements are relevant for teams planning a dedicated server.

What is good

  • Accepts PCAP files, Zeek logs and Suricata alerts
  • Supports live capture forwarded by lightweight sensors
  • Session enrichment includes GeoIP and JA4 fingerprinting
  • Authentication options include LDAP and Keycloak
  • Licensed under Apache License 2.0

What to know first

  • Dedicated server minimum is 8 CPU cores and 24 GB RAM
  • Optimal experience recommends 16 or more cores and 32 GB or more RAM
  • Deployment uses containers or Kubernetes

Inferse review

Malcolm: the full review

Malcolm brings capture analysis, session discovery and traffic enrichment together in a free, self-hosted suite. Its deployment and server requirements make the infrastructure commitment a key consideration.

Overview

Malcolm is a self-hosted network security monitoring suite for teams investigating traffic across captures, logs, and live feeds. It is best suited to security operations that can support containerized infrastructure and want session discovery alongside enriched network context.

Its strongest case is the combination of Arkime session analysis, OpenSearch visualizations, and data enrichment. This is a more substantial deployment than a desktop packet viewer: a dedicated server needs at least 8 CPU cores and 24 GB of RAM, with 16 or more cores and 32 GB or more RAM recommended for an optimal experience.

Key features

  • Multiple traffic inputs: Analysts can submit PCAP files, Zeek logs, and Suricata alerts through a browser interface, or use live capture forwarded by lightweight sensors. PCAP and PCAPNG support and offline trace analysis make it useful for investigations of stored evidence; live capture extends that workflow to ongoing monitoring.
  • Session search and visualization: Arkime supports finding and identifying network sessions, while OpenSearch Dashboards provides visualizations. That pairing serves teams that need both a broad view of traffic and a way to locate particular sessions.
  • Context enrichment: Malcolm adds GeoIP, hardware manufacturer lookups, asset inventory mappings, and JA4 fingerprinting to session data. These enrichments can help analysts interpret traffic in relation to locations, devices, and mapped assets rather than relying on packet data alone.
  • Protocol and ecosystem coverage: Zeek and Arkime analyze documented protocols including DNS, HTTP, Modbus, and BACnet. The documented components also include Suricata, OpenSearch, NetBox, MISP, TAXII, Google, and Mandiant threat intelligence sources, making Malcolm relevant to teams working across network monitoring, asset inventory, and threat intelligence systems.
  • Deployment and access controls: Malcolm runs in Docker or Podman containers, with Kubernetes deployment described for on-premises environments and AWS. Its interface requires authentication and supports local TLS-encrypted basic authentication, LDAP, and Keycloak; role-based access control and Keycloak group and realm role restrictions provide ways to limit access. These controls suit shared deployments, but the container and server requirements still demand infrastructure ownership.

Pricing

Malcolm — 0.00 USD per free (Apache License 2.0 · Self-hosted software). The free plan is the complete project offering described here, with no paid tier or seat-based charge to weigh. Its practical cost is operational: teams need to provide and maintain the deployment environment, including the recommended server resources for an optimal experience.

Platforms

Malcolm supports Linux, Windows 10 or later, and recent macOS releases as Docker hosts, and provides a web interface and REST API. It can be deployed with Docker or Podman, or with Kubernetes on premises or in AWS. Its platform breadth does not make it a lightweight endpoint tool: the dedicated-server baseline of 8 CPU cores and 24 GB of RAM is a substantial requirement for smaller teams.

Who it's for

Malcolm is a strong fit for security teams that need to investigate offline captures and live traffic in one self-hosted environment, especially when session search, protocol analysis, asset mappings, and threat intelligence context matter. Teams already comfortable operating containers and allocating server-class resources can use its breadth without a license fee. It is a poor fit for individual users seeking quick packet inspection on a modest workstation or organizations that do not want to operate their own analysis stack.

Pros and cons

  • Pros: Free, Apache-licensed self-hosted software keeps license fees out of the decision; PCAP and PCAPNG, Zeek logs, Suricata alerts, and forwarded live captures cover varied investigation inputs; enrichment and integrations connect traffic analysis with asset and threat context; authentication options and role-based controls support shared access.
  • Cons: The minimum dedicated-server requirement of 8 CPU cores and 24 GB of RAM raises the infrastructure bar; recommended resources are higher still at 16 or more cores and 32 GB or more RAM; container-based deployment and maintenance are a poor match for teams seeking a simple desktop capture utility.

Alternatives

Network Packet Capture Software is the broader category for comparing packet capture tools. Choose Arkime when session search is the priority: it is free, self-hosted, and has no paid-only features or license fees, while Malcolm brings Arkime together with additional analysis and enrichment components.

Termshark is a free alternative for Linux, macOS, Windows, and Android, though it requires tshark in PATH, needs tshark v1.10.2 or newer, and does not expose some tshark features. NetworkMiner offers a free edition and GPLv2 open-source code written in managed C# on the Microsoft .NET Framework.

PCAPdroid suits Android users seeking core network monitoring and capture at no cost; its paid features are excluded from the free plan, and the paid features are a one-time purchase. Sniffnet is a fully free, open-source option for Linux, macOS, and Windows under MIT or Apache-2.0. For command-line capture, tcpdump is free and BSD-licensed, with capture permission dependent on operating system and configuration; TShark and Wireshark are also free options for Linux, macOS, and Windows.

Verdict

Choose Malcolm if your security team needs self-hosted analysis spanning offline traces and live feeds, with session discovery, visualizations, and enriched network context in one suite. Its free Apache-licensed software is compelling when you can support the infrastructure; look elsewhere if you need lightweight desktop packet capture or cannot dedicate server-class resources to deployment.

Compared on network packet capture software

Free plan
Yescisagov.github.io
Live capture
Yescisagov.github.io
Offline trace analysis
Yescisagov.github.io
Display filters
Yescisagov.github.io
Capture file formats
PCAP, PCAPNGcisagov.github.io
Command-line capture
Yescisagov.github.io
Supported platforms
Linux, Windows, macOS, web browser, REST APIcisagov.github.io

Facts

Purpose
Malcolm is a network traffic analysis tool suite for network security monitoring.cisagov.github.io · 29 Sept 2026
Input data
It accepts PCAP files, Zeek logs, and Suricata alerts through a browser interface or from live capture forwarded by lightweight sensors.cisagov.github.io · 29 Sept 2026
Analysis interfaces
It provides OpenSearch Dashboards for visualizations and Arkime for finding and identifying network sessions.cisagov.github.io · 29 Sept 2026
Data enrichment
Malcolm enriches network session data with GeoIP, hardware manufacturer lookups, asset inventory mappings, and JA4 fingerprinting.cisagov.github.io · 29 Sept 2026
Integrations
Its documented components include Zeek, Suricata, Arkime, OpenSearch, NetBox, MISP, TAXII, Google, and Mandiant threat intelligence sources.cisagov.github.io · 29 Sept 2026
Deployment
Malcolm runs in containers using Docker or Podman, and documentation also describes Kubernetes deployment on premises or in AWS.cisagov.github.io · 29 Sept 2026
Host platforms
The recommended requirements page says Malcolm runs on Docker on recent Linux and macOS releases and Windows 10 or later.cisagov.github.io · 29 Sept 2026
System requirements
A dedicated server requires at least 8 CPU cores and 24 GB of RAM; the developers recommend 16 or more cores and 32 GB or more RAM for an optimal experience.cisagov.github.io · 29 Sept 2026
Security
Malcolm requires authentication for its user interface and supports local TLS-encrypted basic authentication, LDAP, and Keycloak authentication.cisagov.github.io · 29 Sept 2026
Access control
The documentation describes role-based access control and Keycloak group and realm role restrictions for limiting which users can authenticate.cisagov.github.io · 29 Sept 2026
Protocol coverage
Malcolm uses Zeek and Arkime to analyze traffic across documented protocols including DNS, HTTP, Modbus, and BACnet.cisagov.github.io · 29 Sept 2026
License
The project says it is licensed under the Apache License, version 2.0.cisagov.github.io · 29 Sept 2026

Best Malcolm alternatives

See all 19