#suricata — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #suricata, aggregated by home.social.
-
Great news! We’ve been invited to do a 4 hour workshop training for Security BSides Las Vegas 2026!
Join us for “Engineering the Hunt: Developing AI SKILLs for Network Security Monitoring” with Peter Manev, Jeff Lucovsky & Lukas Sismis on August 3rd at 3pm PST.
Learn more: bsideslv.org
-
Great news! We’ve been invited to do a 4 hour workshop training for Security BSides Las Vegas 2026!
Join us for “Engineering the Hunt: Developing AI SKILLs for Network Security Monitoring” with Peter Manev, Jeff Lucovsky & Lukas Sismis on August 3rd at 3pm PST.
Learn more: bsideslv.org
-
Great news! We’ve been invited to do a 4 hour workshop training for Security BSides Las Vegas 2026!
Join us for “Engineering the Hunt: Developing AI SKILLs for Network Security Monitoring” with Peter Manev, Jeff Lucovsky & Lukas Sismis on August 3rd at 3pm PST.
Learn more: bsideslv.org
-
Great news! We’ve been invited to do a 4 hour workshop training for Security BSides Las Vegas 2026!
Join us for “Engineering the Hunt: Developing AI SKILLs for Network Security Monitoring” with Peter Manev, Jeff Lucovsky & Lukas Sismis on August 3rd at 3pm PST.
Learn more: bsideslv.org
-
Great news! We’ve been invited to do a 4 hour workshop training for Security BSides Las Vegas 2026!
Join us for “Engineering the Hunt: Developing AI SKILLs for Network Security Monitoring” with Peter Manev, Jeff Lucovsky & Lukas Sismis on August 3rd at 3pm PST.
Learn more: bsideslv.org
-
CW: release notes for Malcolm v26.07.1, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the
strelka-backendcontainer on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Co-installation of
opencv-pythonandopencv-contrib-pythoncorruptscv2.abi3.so, segfaultingstrelka-backendat import on arm64 #1046 (fix) - Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
- Co-installation of
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash to v9.4.4
- Pillow (Python library used in the
netboxcontainer) to v12.3.0 to address several security findings - Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
- Minor improvements to the Hedgehog Raspberry Pi image build process.
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
CW: release notes for Malcolm v26.07.1, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the
strelka-backendcontainer on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Co-installation of
opencv-pythonandopencv-contrib-pythoncorruptscv2.abi3.so, segfaultingstrelka-backendat import on arm64 #1046 (fix) - Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
- Co-installation of
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash to v9.4.4
- Pillow (Python library used in the
netboxcontainer) to v12.3.0 to address several security findings - Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
- Minor improvements to the Hedgehog Raspberry Pi image build process.
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
CW: release notes for Malcolm v26.07.1, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the
strelka-backendcontainer on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Co-installation of
opencv-pythonandopencv-contrib-pythoncorruptscv2.abi3.so, segfaultingstrelka-backendat import on arm64 #1046 (fix) - Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
- Co-installation of
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash to v9.4.4
- Pillow (Python library used in the
netboxcontainer) to v12.3.0 to address several security findings - Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
- Minor improvements to the Hedgehog Raspberry Pi image build process.
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
CW: release notes for Malcolm v26.07.1, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the
strelka-backendcontainer on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Co-installation of
opencv-pythonandopencv-contrib-pythoncorruptscv2.abi3.so, segfaultingstrelka-backendat import on arm64 #1046 (fix) - Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
- Co-installation of
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash to v9.4.4
- Pillow (Python library used in the
netboxcontainer) to v12.3.0 to address several security findings - Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
- Minor improvements to the Hedgehog Raspberry Pi image build process.
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
Let’s give it up for the sponsors making #SuriCon2026 possible: OPNsense, Léargas Security, Corelight, Stamus Networks, ENEA, Catena Cyber, NEOX, Nomic Networks, and AWS.
Sponsorship opportunities are still available! Help bring this community together in 2026! suricon.net/sponsorships/
-
Let’s give it up for the sponsors making #SuriCon2026 possible: OPNsense, Léargas Security, Corelight, Stamus Networks, ENEA, Catena Cyber, NEOX, Nomic Networks, and AWS.
Sponsorship opportunities are still available! Help bring this community together in 2026! suricon.net/sponsorships/
-
Let’s give it up for the sponsors making #SuriCon2026 possible: OPNsense, Léargas Security, Corelight, Stamus Networks, ENEA, Catena Cyber, NEOX, Nomic Networks, and AWS.
Sponsorship opportunities are still available! Help bring this community together in 2026! suricon.net/sponsorships/
-
Let’s give it up for the sponsors making #SuriCon2026 possible: OPNsense, Léargas Security, Corelight, Stamus Networks, ENEA, Catena Cyber, NEOX, Nomic Networks, and AWS.
Sponsorship opportunities are still available! Help bring this community together in 2026! suricon.net/sponsorships/
-
Let’s give it up for the sponsors making #SuriCon2026 possible: OPNsense, Léargas Security, Corelight, Stamus Networks, ENEA, Catena Cyber, NEOX, Nomic Networks, and AWS.
Sponsorship opportunities are still available! Help bring this community together in 2026! suricon.net/sponsorships/
-
CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.0
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash OSS to v9.4.3
- Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
❌ Errata
- Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.0
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash OSS to v9.4.3
- Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
❌ Errata
- Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.0
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash OSS to v9.4.3
- Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
❌ Errata
- Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.0
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash OSS to v9.4.3
- Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
❌ Errata
- Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.0
✨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
🛡️ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
🐛 Bug fixes
- Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
✅ Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash OSS to v9.4.3
- Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
🧹 Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
📄 Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
❌ Errata
- Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
EveBox can now process PCAP files directly and take care of processing with #Suricata for you. Only on Linux right now. But I plan to fix that.
-
EveBox can now process PCAP files directly and take care of processing with #Suricata for you. Only on Linux right now. But I plan to fix that.
-
EveBox can now process PCAP files directly and take care of processing with #Suricata for you. Only on Linux right now. But I plan to fix that.
-
EveBox can now process PCAP files directly and take care of processing with #Suricata for you. Only on Linux right now. But I plan to fix that.
-
EveBox can now process PCAP files directly and take care of processing with #Suricata for you. Only on Linux right now. But I plan to fix that.
-
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
SuriCon is community-funded - sponsorships keep it self-sustaining.
Spots remain from the $800 Mob tier (for individual super fans) up to Community Partner ($10K).
And our last exclusive slot: Welcome Reception Sponsor ($6K).
Secure your spot: suricon.net/sponsorships/
-
SuriCon is community-funded - sponsorships keep it self-sustaining.
Spots remain from the $800 Mob tier (for individual super fans) up to Community Partner ($10K).
And our last exclusive slot: Welcome Reception Sponsor ($6K).
Secure your spot: suricon.net/sponsorships/
-
SuriCon is community-funded - sponsorships keep it self-sustaining.
Spots remain from the $800 Mob tier (for individual super fans) up to Community Partner ($10K).
And our last exclusive slot: Welcome Reception Sponsor ($6K).
Secure your spot: suricon.net/sponsorships/
-
SuriCon is community-funded - sponsorships keep it self-sustaining.
Spots remain from the $800 Mob tier (for individual super fans) up to Community Partner ($10K).
And our last exclusive slot: Welcome Reception Sponsor ($6K).
Secure your spot: suricon.net/sponsorships/
-
SuriCon is community-funded - sponsorships keep it self-sustaining.
Spots remain from the $800 Mob tier (for individual super fans) up to Community Partner ($10K).
And our last exclusive slot: Welcome Reception Sponsor ($6K).
Secure your spot: suricon.net/sponsorships/
-
Got tired of mucking with these miserable #screenconnect msi's so here's a #suricata rule to catch the initial check via sni:
https://gist.github.com/silence-is-best/29afec335264313e9bf5bfa1c6e60144
https://app.any.run/tasks/73887f39-a8ac-4702-a67d-36465caca294
cc @da_667 -
Got tired of mucking with these miserable #screenconnect msi's so here's a #suricata rule to catch the initial check via sni:
https://gist.github.com/silence-is-best/29afec335264313e9bf5bfa1c6e60144
https://app.any.run/tasks/73887f39-a8ac-4702-a67d-36465caca294
cc @da_667 -
Got tired of mucking with these miserable #screenconnect msi's so here's a #suricata rule to catch the initial check via sni:
https://gist.github.com/silence-is-best/29afec335264313e9bf5bfa1c6e60144
https://app.any.run/tasks/73887f39-a8ac-4702-a67d-36465caca294
cc @da_667 -
Got tired of mucking with these miserable #screenconnect msi's so here's a #suricata rule to catch the initial check via sni:
https://gist.github.com/silence-is-best/29afec335264313e9bf5bfa1c6e60144
https://app.any.run/tasks/73887f39-a8ac-4702-a67d-36465caca294
cc @da_667 -
Got tired of mucking with these miserable #screenconnect msi's so here's a #suricata rule to catch the initial check via sni:
https://gist.github.com/silence-is-best/29afec335264313e9bf5bfa1c6e60144
https://app.any.run/tasks/73887f39-a8ac-4702-a67d-36465caca294
cc @da_667 -
The Hunters Ledger ruleset was recently added to the #Suricata ruleset index; check it out here: https://the-hunters-ledger.com/
Thank you Joseph Harrison (https://www.linkedin.com/in/josephrharrison/)
-
The Hunters Ledger ruleset was recently added to the #Suricata ruleset index; check it out here: https://the-hunters-ledger.com/
Thank you Joseph Harrison (https://www.linkedin.com/in/josephrharrison/)
-
The Hunters Ledger ruleset was recently added to the #Suricata ruleset index; check it out here: https://the-hunters-ledger.com/
Thank you Joseph Harrison (https://www.linkedin.com/in/josephrharrison/)
-
The Hunters Ledger ruleset was recently added to the #Suricata ruleset index; check it out here: https://the-hunters-ledger.com/
Thank you Joseph Harrison (https://www.linkedin.com/in/josephrharrison/)
-
The Hunters Ledger ruleset was recently added to the #Suricata ruleset index; check it out here: https://the-hunters-ledger.com/
Thank you Joseph Harrison (https://www.linkedin.com/in/josephrharrison/)
-
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.
The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/
#Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity