Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
Malcolm v23.09.0 is a release containing enhancements and bug fixes.
https://github.com/cisagov/Malcolm/compare/v23.08.1...v23.09.0
Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.
Malcolm v23.08.1 is a patch release fixing a regression in Hedgehog Linux which would cause disks to not be detected and used for artifact storage.
https://github.com/cisagov/Malcolm/compare/v23.08.0...v23.08.1
Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.
Malcolm v23.08.0 is a minor release with a few improvements, bug fixes and component updates.
EDIT: I've discovered a regression in the Hedgehog Linux startup script that formats drives to make them available for artifact capture. I'm investigating now. If this affects you, you might want to avoid this release until I put out a patch.
https://github.com/cisagov/Malcolm/compare/v23.07.1...v23.08.0
Features and enhancements
Bug fixes
Component version updates
Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.
Malcolm v23.07.1 is a patch release fixing a single bug.
https://github.com/cisagov/Malcolm/compare/v23.07.0...v23.07.1
Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.
EDIT - A bug in how Modbus traffic was parsed was discovered shortly after this release. A v23.07.1 release will be put out in the next day or so, you may want to wait for that.
Malcolm v23.07.0 is a feature release with a number of improvements, bux fixes and component updates.
https://github.com/cisagov/Malcolm/compare/v23.05.1...v23.07.0
New features
Enhancements
Bug fixes
-
in pcapng Fails to Upload (cisagov/Malcolm#265)Component version updates
Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.
Malcolm v23.05.1 is a minor release with a few component version updates and bug fixes, particularly to fix an issue with install.py
where the ownership of .env
files in the config
directory may get incorrectly set to root
rather than the unprivileged user.
https://github.com/cisagov/Malcolm/compare/v23.05.0...v23.05.1
Enhancements and bug fixes
http.xff*
) get created in the index template with the right field types to avoid aggregation query issuesmalcolmmonitor
and sensormonitor
) in ISO-installed Malcolm and Hedgehog Linux environments.service
files for the ISO-installed version of Malcolm to be able to feed itself resource statistics via Fluent BitComponent version updates
Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.
Malcolm v23.05.0 is a major release with new features, enhancements, component version updates and bug fixes.
IMPORTANT NOTE: Malcolm v23.05.0 has completely changed the way it manages its settings: rather than using environment variables found at the top of the docker-compose.yml
file, it uses environment variables in .env
files inside of the config
directory. The locations of a number of configuration files have also changed. It's not recommended to update to Malcolm v23.05.0 from a previous version of Malcolm. Instead, shut down Malcolm, rename your old Malcolm installation directory to something else, and reconfigure Malcolm using ./scripts/configure
and ./scripts/auth_setup
.
https://github.com/cisagov/Malcolm/compare/v23.04.0...v23.05.0
New features
Enhancements and fixes
./scripts/configure
alias for ./scripts/install.py --configure
Component version updates
Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.
Malcolm v23.04.0 is a release with enhancements, component version updates and bug fixes.
IMPORTANT NOTE: In March 2023 Docker Inc. announced its decision to sunset the "Docker Free Team" plan, which prompted us to decide to migrate away from Docker Hub to the Github Container Registry or "ghcr" (see idaholab/Malcolm#163). Due to public backlash, Docker Inc. reversed its decision. However, the Malcolm project will continue with the decision to use GHCR beginning with this release (Malcolm v23.04.0) and moving forward. If you're updating an existing instance of Malcolm, it's recommended that you back up your docker-compose.yml
and docker-compose-standalone.yml
files, replace them with the ones from this release and re-run ./scripts/install.py --configure
to ensure that you're pointing at the latest images (this is actually always good practice when moving to a new release of Malcolm).
https://github.com/cisagov/Malcolm/compare/v23.03.0...v23.04.0
Enhancements
install.py --configure
on Malcolm ISO first boot (idaholab/Malcolm#157)tx-rx-secure.sh
script as wrapper around croc automatically creating and using a local-only relayComponent version updates
Fixes
Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.
Malcolm v23.03.0 is a release with enhancements, component version updates and bug fixes.
https://github.com/cisagov/Malcolm/compare/v23.02.0...v23.03.0
Enhancements
start
and restart
scripts once Malcolm has started properly (cisagov/Malcolm#240 and cisagov/Malcolm#241, thanks @Njinx)./scripts/install.py --configure
in full screen. May look at starting this automatically on first boot in the future. (Malcolm)install.py --configure
(enable offline-capable file scanners by default)netbox-restore
is runreset_and_auto_populate.sh
script (used mostly for demos and presentations)Component version updates
Fixes
scripts
directory, symlink netbox-backup
and netbox-restore
to control.py
pcap_watcher.py
in pcap-monitor
containerMalcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.
Malcolm v23.02.0 is a feature release with new features and enhancements, component version updates and bug fixes.
https://github.com/cisagov/Malcolm/compare/v23.01.0...v23.02.0
New features
netbox-backup
/netbox-restore
scripts to control.py
for NetBox database and mediazeek_script_to_malcolm_boilerplate.py
script for automating some of the tasks involved with adding new Zeek logs to MalcolmEnhancements
tail -n
(cisagov/Malcolm#234, thanks @Njinx)state:storeInSessionStorage
to true
for OpenSearch dashboards: this allows some complicated visualizations to be built with the Vega and Transform plugins, at the cost of having some URL bookmarks not contain every possible state the current dashboard hasrelated.device_name
for normalization and pivotingrelated.segment
in favor of ECS network.name
Component version updates
Fixes
docker-compose
in case for some reason that's not in PATH (?) (cisagov/Malcolm#226)Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.