Malcolm v23.03.0 is a release with enhancements, component version updates and bug fixes.
Malcolm is a powerful, easily deployable (via Docker) network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
Enhancements
start
and restart
scripts once Malcolm has started properly (cisagov/Malcolm#240 and cisagov/Malcolm#241, thanks @Njinx)./scripts/install.py --configure
in full screen. May look at starting this automatically on first boot in the future. (Malcolm)install.py --configure
(enable offline-capable file scanners by default)netbox-restore
is runreset_and_auto_populate.sh
script (used mostly for demos and presentations)Component version updates
Fixes
scripts
directory, symlink netbox-backup
and netbox-restore
to control.py
pcap_watcher.py
in pcap-monitor
container#Malcolm #OpenSearch #Zeek #Arkime #Suricata #PCAP #NetworkTrafficAnalysis #CyberSecurity #Cyber #Infosec #GitHub #INL #DHS #CISA #CISAgov
#netbox #arkime #malcolm #opensearch #zeek #suricata #pcap #networktrafficanalysis #cybersecurity #cyber #infosec #github #inl #dhs #cisa #CISAgov
Did you know that a "pizza party" is a cybersecurity measure?
#cisagov recommends in its "Cross Sector Cybersecurity Performance Goals" (CPG 4.5), that "Organizations sponsor at least one ‘pizza party’ or equivalent social gathering per year that is focused on strengthening working relationships between IT and OT security personnel, and is not a working event (such as providing meals during an incident response). "
#CISAgov #cybersecurity #infosec
Did you know that a "pizza party" is a cybersecurity measure? ...if you invite the right people of course.
#cisagov recommends in its "Cross Sector Cybersecurity Performance Goals" (CPG 4.5), that "Organizations sponsor at least one ‘pizza party’ or equivalent social gathering per year that is focused on strengthening working relationships between IT and OT security personnel, and is not a working event (such as providing meals during an incident response). "
#Malcolm v6.4.3 is a minor #release containing enhancements, component version updates and bug fixes.
Enhancements
install.py --configure
ask about other storage locations for PCAP, Zeek logs and OpenSearch indicesinstall.py --configure
prompt for Arkime to manage uploaded PCAP files or notComponent version updates
Fixes
install.py
memory recommendations#Malcolm and #HedgehogLinux may be obtained by pulling or building the #Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on #GitHub, but may be downloaded from https://malcolm.fyi/.
#cybersecurity #pcap #networktrafficanalysis #zeek #arkime #ICS #INL #CISAgov
#malcolm #release #alpine #filebeat #netbox #zeek #opensearch #fluentbit #hedgehoglinux #docker #github #cybersecurity #pcap #networktrafficanalysis #arkime #ics #inl #CISAgov
I'm pleased to announce the v6.4.2 release of Malcolm. This release updates #Zeek to v5.0.3 and #OpenSearch and #OpenSearchDashboards to v2.4.0 as well as some other minor fixes and improvements. It also includes a Zeek plugin to detect vulnerability to and exploitation attempts of #CVE20223602.
See the documentation for instructions for installing Malcolm and pulling the new #Docker images, or grab the (unofficial) ISOs.
#Malcolm #HedgehogLinux #cybersecurity #pcap #networktrafficanalysis #zeek #arkime #ICS #INL #CISAgov
#zeek #opensearch #opensearchdashboards #CVE20223602 #docker #malcolm #hedgehoglinux #cybersecurity #pcap #networktrafficanalysis #arkime #ics #inl #CISAgov
One topic that comes up at least weekly in my job is Multi Factor Authentication #MFA. Often I am asked about what method is secure. Finally I can tell them #Fido2 / #WebAuthn , forget sms, voice or #TOTP ...and by the way, you can read it here #CISAgov https://www.cisa.gov/uscert/ncas/current-activity/2022/10/31/cisa-releases-guidance-phishing-resistant-and-numbers-matching
#mfa #fido2 #webauthn #totp #CISAgov
📛 #CISAgov warning should not come as a surprise because:
⚠️900 #PulseSecure VPN servers data leaked recently.
⚠️#MicrosoftExchange server exploited in March 2020.
⚠️Hackers stole 6TB of data from #CitrixVPN in 2019.
#CitrixVPN #MicrosoftExchange #pulsesecure #CISAgov