forked from cisagov/Malcolm
-
Notifications
You must be signed in to change notification settings - Fork 62
Malcolm Learning Tree
Seth Grover edited this page Mar 20, 2024
·
8 revisions
The purpose of this page is to divide and arrange Malcolm training topics into a logical sequence.
- Malcolm
- Installation
- Configuration
- Configuring Malcolm
- [Running Malcolm(https://github.com/idaholab/Malcolm#351)
- Ingesting traffic
- Capturing Live Network Traffic for Analysis
- Uploading PCAP for Analysis
- (link to Hedgehog section)
- Authentication and User Management
- Using a Remote OpenSearch or Elasticsearch Instance
- Managing OpenSearch/Elasticsearch Indexes
- OpenSearch Dashboards
- Overview (video done in phase 1?)
- Pre-built Dashboards
- Queries and Filters
- Notices and Signatures
- Discover
- Anomaly Detection
- Creating Custom Dashboards
- Alerting
- Arkime
- Overview (video done in phase 1?)
- Sessions
- SPIView
- SPIGraph
- Connections
- Hunt
- NetBox
- Overview (video done in phase 1?)
- Manual Inventory Population
- Automatic Inventory Population
- Asset Interaction Analysis
- Backing up and Restoring the NetBox Inventory
- Other Analysis Topics
- Hedgehog Linux