Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

plugin architecture: custom rules/policy/scripts/config/etc. #366

Open
mmguero opened this issue Nov 4, 2024 · 0 comments
Open

plugin architecture: custom rules/policy/scripts/config/etc. #366

mmguero opened this issue Nov 4, 2024 · 0 comments
Labels
arkime Relating to Malcolm's use of Arkime carving Relating to carving (extraction) of files from traffic and the scanning of those files enhancement New feature or request plugins Related to Malcolm "plugins" suricata Relating to Malcolm's use of Suricata zeek Relating to Malcolm's use of Zeek
Milestone

Comments

@mmguero
Copy link
Collaborator

mmguero commented Nov 4, 2024

@mmguero cloned issue idaholab/Malcolm#581 on 2024-10-01:

This is a sub-issue of Malcolm "plugin architecture" #399

One type of plugin could contain custom rules, policy, or configuration. Basically anything covered in "policy manager" for Malcolm and Hedgehog Linux (there is some overlap between that feature and this one)

Also, I want to include everything talked about in Custom Rules, Scripts, and Plugins here in this issue. Anything that the user could create by dropping the files described in that documentation into a plugin ought to be handled as well.

@mmguero mmguero added arkime Relating to Malcolm's use of Arkime carving Relating to carving (extraction) of files from traffic and the scanning of those files enhancement New feature or request plugins Related to Malcolm "plugins" suricata Relating to Malcolm's use of Suricata zeek Relating to Malcolm's use of Zeek labels Nov 4, 2024
@mmguero mmguero added this to Malcolm Nov 5, 2024
@mmguero mmguero added this to the z.staging milestone Nov 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
arkime Relating to Malcolm's use of Arkime carving Relating to carving (extraction) of files from traffic and the scanning of those files enhancement New feature or request plugins Related to Malcolm "plugins" suricata Relating to Malcolm's use of Suricata zeek Relating to Malcolm's use of Zeek
Projects
Status: No status
Development

No branches or pull requests

1 participant