Malcolm
Malcolm is a free open source tool that focuses on data collection and analysis. It is the result of a collaboration between the Idaho National Laboratory and the United States Department of Homeland Security (DHS). More specifically, the contributions come from the somewhat infamous Cybersecurity Infrastructure Security Agency (CISA), which is an agency within DHS. In this vein, you might be interested to learn that Malcolm is not technically a single piece of software but a collection of many open source tools, including the rest of the tools in both this and the next chapter! If you think about it, that’s what Kali Purple is, right? So, we have a collection of tools within another collection of tools. That should give you an idea of the overall depth of Kali Purple.
The idea of Malcolm being a collection of tools can sometimes confuse people because some of these tools are well-known. Two such tools will be covered later in this chapter – Arkime and CyberChef...