Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Capturing Live Network Traffic for Analysis #353

Closed
mmguero opened this issue Jan 15, 2024 · 2 comments
Closed

Capturing Live Network Traffic for Analysis #353

mmguero opened this issue Jan 15, 2024 · 2 comments
Labels
capture Relating to pcap-capture container train-configuration Training topic relating to installation or configuration training Related to developing and releasing Malcolm training

Comments

@mmguero
Copy link
Collaborator

mmguero commented Jan 15, 2024

For what topic would you like to see training developed?
Describe the ways Malcolm can analyze live network traffic: via a sensor device (Hedgehog Linux) or by monitoring local network interfaces.

What format would be best suited for this training?
A video

Is there existing Malcolm documentation that could be improved by including this topic?
Live analysis

@mmguero mmguero added the training Related to developing and releasing Malcolm training label Jan 15, 2024
@mmguero mmguero added the train-configuration Training topic relating to installation or configuration label Feb 16, 2024
@mmguero
Copy link
Collaborator Author

mmguero commented Feb 26, 2024

Some notes for consideration:

  • time zones / time filters
  • sensors vs. Malcolm time in sync
  • differences in live vs. PCAP-uploaded traffic

@mmguero mmguero added the capture Relating to pcap-capture container label Feb 26, 2024
@mmguero mmguero changed the title Live analysis Capturing Live Network Traffic for Analysis Mar 20, 2024
@mmguero
Copy link
Collaborator Author

mmguero commented Nov 5, 2024

Kamino closed and cloned this issue to cisagov/Malcolm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
capture Relating to pcap-capture container train-configuration Training topic relating to installation or configuration training Related to developing and releasing Malcolm training
Projects
Status: Migrated
Development

No branches or pull requests

1 participant