RE: https://infosec.exchange/@zeek/116597071508656812
Zeek 8.2 bump: the docs redesign is a big one. Be sure to check out our new tutorial that covers command line, packages, logs, cluster, and scripting basics in one place:
RE: https://infosec.exchange/@zeek/116597071508656812
Zeek 8.2 bump: the docs redesign is a big one. Be sure to check out our new tutorial that covers command line, packages, logs, cluster, and scripting basics in one place:
This is the guitar and practice - for stage - side of my 'Resonance Loft Sound Studio' - I am now working on the recording and keyboard side of my studio.
#ztf #zรฉรจk #resonanceloftsoundstudio #indieartist #independantartist
I built IT PCAP Triage - a small offline tool for people who hate digging through PCAPs manually.
It runs Zeek, Suricata, capinfos and tshark, then generates a compact HTML security report with findings, risky hosts, DNS/TLS/SMB/HTTP summaries, IDS alerts and evidence.
Still not a SIEM. Still not magic. Just automation for the boring first triage pass.
Consider bookmarking this one if you're working on custom protocol parsers in Spicy. Evan's tutorial covers the full workflow:

Malcolm v26.05.2 is out?!? What, already? Dรฉjร vu? We bumped up to the timetable on this release as a critical vulnerability found in NGINX made it expedient for us to do so.
Malcolm v26.05.2 focuses heavily on security updates, most notably upgrading OpenResty to address a critical NGINX remote code execution heap buffer overflow vulnerability. It also adds new Suricata OT detections for D-Link HNAP abuse, improves alerting webhook support, introduces the File Tree dashboard, and includes Suricata parsing/mapping fixes and documentation updates. Several other components received version bumps as well.
If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.
https://github.com/idaholab/Malcolm/compare/v26.05.0...v26.05.2
filescan's python-statfs (#960 #962)suricata.tc_progress, suricata.ts_progress, suricata.tunnel.pcap_cnt, suricata.tunnel.pkt_src) to the index mapping templatesuricata.app_proto_ts and/or suricata.app_proto_tc reported that protocol parsing had failed (due to malformed input data), invalid data could be stored in HTTP, DNS, and/or TLS fields. This is now detected and those invalid values are dropped, and some combination of proto_parse_failed, client_stream_failed, or server_stream_failed are added to tags.network.protocol_version.Malcolm is a powerful, easily deployable network ๐ง traffic analysis tool suite for network security monitoring ๐ต๐ปโโ๏ธ.
Malcolm operates as a cluster of containers ๐ฆ, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker ๐, Podman ๐ฆญ, and Kubernetes โ. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images ๐ฟ for Malcolm and Hedgehog Linux ๐ฆ can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split ๐ช into 2GB chunks and can be reassembled with scripts provided for both Bash ๐ง (release_cleaver.sh) and PowerShell ๐ช (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.
As always, join us on the Malcolm discussions board ๐ฌ to engage with the community, or pop some corn ๐ฟ and watch a video ๐ผ.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
Zeek 8.2 is out (the final stop before Zeek 9!).
Highlights: &publish_on_change for cluster state propagation, ZeroMQ CURVE encryption, Spicy 1.16, and a fully redesigned docs site.
The team was busy
Zeek Workshop Berkeley 2026 CFP is open
If you know someone who works with Zeek, send them our way - https://zeek.org/zeek-workshop-berkeley-2026/call-for-presentations-berkeley/
Malcolm v26.05.0 delivers a mix of feature improvements, performance improvements, bug fixes, dependency updates, and deployment refinements across Malcolm and Hedgehog for both Docker- and Kubernetes-based workflows.
If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.
https://github.com/idaholab/Malcolm/compare/v26.04.1...v26.05.0
./netbox/custom-scripts and automatic script registration at startupnetbox/scripts to netbox/control-scriptsfile.strings extraction/indexing/search support across Strelka โ Logstash โ OpenSearch templates (wildcard field mapping type) โ Arkime/WISEZEEK_FILE_ANALYZER_TIMEOUT_SECnetdev users in ISO-installed environment can run nmcli and nmtui to configure network interfaces.malcolm_appliance_packager.sh script that creates a tarball of Malcolm images can now package for both Malcolm and Hedgehog profiles.0sensor on first login and disables direct root password login by default.github/workflows/raspi-build-push.ymlstop --wipekubernetes/01-volumes-nfs.yml.example for the filescan volume sectionopensearch is no longer part of the hedgehog Docker Compose profile, and some depends_on relationships were adjusted accordingly./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.ZEEK_FILE_ANALYZER_TIMEOUT_SEC (default 5) to zeek.env. This is the default amount of time a file can be inactive before the file analysis gives up and discards any internal state related to the file.ZEEK_CLUSTER_BACKEND can be specified in zeek.env to specify the Zeek cluster backend (ZeroMQ vs Broker).Malcolm is a powerful, easily deployable network ๐ง traffic analysis tool suite for network security monitoring ๐ต๐ปโโ๏ธ.
Malcolm operates as a cluster of containers ๐ฆ, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker ๐, Podman ๐ฆญ, and Kubernetes โ. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images ๐ฟ for Malcolm and Hedgehog Linux ๐ฆ can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split ๐ช into 2GB chunks and can be reassembled with scripts provided for both Bash ๐ง (release_cleaver.sh) and PowerShell ๐ช (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.
As always, join us on the Malcolm discussions board ๐ฌ to engage with the community, or pop some corn ๐ฟ and watch a video ๐ผ.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
Join us in-person at Zeek Workshop Berkeley 2026!
September 10-11 at the David Brower Center in Berkeley, CA.
Free to attend. Registration open now:
https://zeek.org/zeek-workshop-berkeley-2026/registration-berkeley/