Malcolm

Web · Windows · Mac · Linux · Self-hosted · API

Freedom report

Two barsScore 5.7

  • Free tierNo free tier on record
  • Open codeNo open-source code on record
  • Runs widely4 of 6 device platforms
  • DocumentedPlans, terms and facts published

Malcolm is a network traffic analysis suite for security monitoring. It accepts PCAP files, Zeek logs, and Suricata alerts through a browser, or can process live traffic sent by lightweight forwarders. Session data can be enriched with GeoIP, MAC-vendor, asset-inventory, and JA4 fingerprinting information. Analysts can examine traffic in OpenSearch Dashboards with prebuilt dashboards, or search and identify sessions in Arkime. Malcolm runs as containers and can be deployed with Docker, Podman, or Kubernetes; a standalone Debian-based installer ISO is also available. The project provides host-configuration documentation for Linux, macOS, and Windows. Authentication options documented include local accounts, LDAP, TLS certificates, and Keycloak. Communications from the interface and remote log forwarders use industry-standard encryption protocols. Malcolm is free, and its source code is released under Apache License 2.0. One deployment limitation is specific to rootless Podman: it cannot capture traffic on local network interfaces, though it can accept metadata forwarded by a network sensor appliance.

Who it is for

Malcolm is aimed at security operations centers, smaller networks, home environments, and field incident-response work. It may suit analysts who need to examine PCAP files, logs, or forwarded live traffic through browser interfaces.

What is good

  • Accepts PCAP files, Zeek logs, and Suricata alerts.
  • Can process live traffic from lightweight forwarders.
  • Includes OpenSearch Dashboards and Arkime analysis interfaces.
  • Free software released under Apache License 2.0.
  • Supports Docker, Podman, and Kubernetes deployments.

What to know first

  • Rootless Podman cannot capture local network interfaces.
  • Installer formats all non-removable storage without warning.
  • Requires deployment as containers or a Debian-based installer ISO.

Freedom251 review

Malcolm: the full review

Malcolm combines traffic intake, enrichment, and browser-based analysis for security monitoring. Plan deployments carefully, particularly if using rootless Podman or the installer ISO.

Overview

Malcolm is a self-hosted network security monitoring suite for teams that need to collect traffic and investigate sessions in one environment. It suits security operations centers, smaller networks, home environments, and field incident-response work. Its broad ingestion and analysis stack is compelling, but deployment choices matter: rootless Podman cannot capture directly from local interfaces, and the installer ISO can repartition non-removable storage without warning.

Key features

Collection and context

Malcolm accepts PCAP files, Zeek logs, and Suricata alerts. Analysts can upload data in a browser or capture live traffic and relay it with lightweight forwarders. That range makes it useful both for reviewing existing captures and for feeding ongoing monitoring, though rootless Podman users must rely on forwarded metadata rather than local-interface capture.

Session enrichment adds GeoIP, MAC-vendor, asset-inventory, and JA4 fingerprint lookups. These fields can help analysts place network activity in geographic, device, and inventory context without treating raw sessions as the whole picture.

Investigation and integrations

OpenSearch Dashboards supplies prebuilt dashboards, while Arkime supports searching and identifying network sessions. Both are browser-based, so analysts can work from workstations or SOC displays. Malcolm also offers a REST API that forwards requests to Logstash, OpenSearch, NetBox, and Arkime APIs.

The suite combines components including Zeek, Suricata, Strelka, YARA, Capa, ClamAV, MISP, TAXII, PostgreSQL, Valkey, and Keycloak. This breadth supports varied monitoring workflows, but it also means Malcolm is a container-based stack rather than a small standalone packet viewer. The project is developing additional parsers for industrial-control-system protocols.

Security and deployment

Malcolm can run with Docker, Podman, or Kubernetes, including AWS Kubernetes deployments, and is also available as a Debian-based installer ISO. Its documentation covers Linux, macOS, and Windows host configuration. Communications from the interface and remote log forwarders use industry-standard encryption; authentication options include local accounts, LDAP, TLS certificates, and Keycloak roles.

Official container images are automatically scanned with Trivy for vulnerabilities and misconfigurations. The ISO-installed aggregator uses hardening scripts aimed at CIS recommendations and adapted DISA STIG checks. These measures are useful for organizations planning a managed deployment, but they do not remove the need to choose and configure the deployment model carefully. The ISO will partition and format all non-removable storage without warning and offers no partitioning confirmations, so it is a poor choice for a machine with data to preserve.

Pricing

Malcolm is free, with no paid plan or trial term described. Its source code is released under the Apache License, Version 2.0. The free model avoids per-seat or subscription costs, while the practical commitment is running and maintaining the container stack or preparing an appropriate host for the installer.

Platforms

Malcolm supports Linux, macOS, and Windows hosts, with browser access to its analysis interfaces. It is self-hosted and exposes an API. Live capture and PCAP-file analysis are both supported, alongside Zeek logs and Suricata alerts.

Who it's for

Malcolm is best suited to security teams that want a self-hosted pipeline spanning traffic intake, enrichment, dashboards, and session search. Its stated scope also includes smaller networks, home use, and field incident response. Teams that need a simple one-purpose capture utility, or cannot operate a multi-container environment, may prefer a narrower tool.

Pros and cons

Pros

  • Multiple ways to feed investigations: PCAP uploads, live capture, Zeek logs, Suricata alerts, and forwarded metadata cover both retrospective and ongoing analysis.
  • Useful session context: GeoIP, vendor, inventory, and JA4 enrichments add information beyond the captured traffic itself.
  • Two browser analysis interfaces: Prebuilt OpenSearch dashboards and Arkime session search support different investigation tasks.
  • Flexible deployment and authentication: Container options, an installer ISO, LDAP, certificates, and Keycloak roles accommodate different operating environments.

Cons

  • Rootless Podman cannot capture local interfaces: Operators using that setup need a separate sensor to forward metadata.
  • The ISO can erase storage without confirmation: Its automatic formatting behavior makes careful host selection essential.
  • It requires deployment ownership: Malcolm runs as a container cluster or installed aggregator, which is a larger operational commitment than a focused capture tool.

Alternatives

NETCAP is worth considering when an open-source CLI with 66+ audit record types is a closer fit; it also has a free Core plan and a paid Pro plan at 548.00 USD per month.

PacketSafari is another freemium option for readers comparing packet-analysis tools.

Scapy is a free Python 3.7+ option under GPLv2 for readers looking for a different open-source tool.

NetworkMiner may suit readers seeking a free edition of a GPLv2, managed C# application.

Sniffnet is a free, open-source option under MIT or Apache-2.0 for readers who want a different lightweight network utility.

tcpdump is a free BSD-licensed alternative when command-line capture is the priority; capture permissions depend on operating system and configuration.

TShark is a free GNU GPL v2 alternative for readers who want a command-line network tool.

Wireshark is a free full-version alternative with no license fee.

Browse the Network Packet Analyzer Software category for more options.

Verdict

Choose Malcolm if your security team wants a free, self-hosted monitoring stack that combines several traffic inputs, contextual enrichment, dashboards, and session search. Look elsewhere if you need uncomplicated local capture under rootless Podman or cannot accept the ISO's unconfirmed disk formatting behavior.

Compared on network packet analyzer software

Free plan
Yes
Live capture
Yes
Command-line tool
Yes
Operating systems
Linux, macOS, Windows
Capture file formats
PCAP
Protocol dissectors
Yes

Best Malcolm alternatives

See all 12