github cisagov/Malcolm v23.12.1
Malcolm v23.12.1

latest releases: v24.02.1, v24.02.0, v24.01.0...
10 months ago

Malcolm v23.12.0 is a minor release with a few updates and bug fixes

v23.12.0...v23.12.1

  • Features and enhancements
    • have install.py offer to pull the docker images (idaholab#310)
    • only overwrite Arkime's config.ini with config.orig.ini if config.ini doesn't already exist (idaholab#311)
    • create Suricata rules for Zyxel vulnerabilities from KEV (idaholab#312)
    • provide alternate configuration for Arkime capture to listen on the interface directly rather than post-processing PCAPs (idaholab#281)
    • added SURICATA_DISABLE_ICS_ALL environment variable to disable OT/ICS analysis in Suricata
    • added ZEEK_INTEL_REFRESH_THREADS to allow setting the number of threads for intel feed pulls
    • documented the different run profiles (hedgehog vs. malcolm profiles) and generally improved documentation of live capture options
    • route /mapi/opensearch/, /mapi/logstash/ and /mapi/netbox/ from the Malcolm API endpoint to their respective component APIs
    • minor improvements to how the user supplies custom rules/config for Suricata, Zeek, and Arkime
  • Component version updates
  • Bug fixes
    • review and fix capabilities granted to containers (idaholab#282)
    • change URL for downloading manuf list to new wireshark.org URL / wireshark no longer publishes raw manuf (OUI) list (idaholab#230 and idaholab#306)
    • directory hierarchies not being created as Kubernetes configmap correctly (idaholab#308)
    • rsyslog no longer in Debian bookworm (idaholab#309)
    • removed unused Arkime log and raw directories

Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.

Don't miss a new Malcolm release

NewReleases is sending notifications on new releases.