Skip to content

Learning

Seth Grover edited this page Nov 19, 2024 · 1 revision

Malcolm Learning Tree

The Malcolm team is always working to develop and improve resources for learning about how to deploy, configure, and use Malcolm. This list organizes learning modules by category with links to the documentation and video resources associated with each topic. If you have an idea or request for a training topic, please let us know by submitting a training issue request or opening a new discussion in the Training category on the discussions board.

Learning topics are also tracked as issues in this project on the Malcolm GitHub repository.

If you're not looking for training per se, the Q&A and Troubleshooting discussion categories are a great place to go for help. Or, if you have a feature request or think you've found a bug in Malcolm, check out the Issue Tracker.

Learning Modules

Category Topic Documentation Video
Overview GitHub Overview πŸ““ πŸ““ πŸ““ πŸ”œ
Overview Malcolm Overview πŸ“” πŸ“Ό
Overview Malcolm Background πŸ”œ πŸ”œ
Overview Malcolm Terms & Definitions πŸ”œ πŸ”œ
General Malcolm Technical Workshop πŸ”œ πŸ”œ
Installation Installing Malcolm Using the Installation ISO πŸ“” πŸ“” πŸ“” πŸ“Ό
Installation Installing Malcolm on Linux Using Docker πŸ“” πŸ“” πŸ“Ό
Installation Installing Malcolm on Microsoft Windows Using WSL & Docker πŸ“” πŸ”œ
Installation Installing Malcolm on macOS Using Docker πŸ“” πŸ”œ
Installation Cloud Deployment: Deploying Malcolm Using Kubernetes πŸ“” πŸ”œ
Installation Cloud Deployment: Deploying Malcolm Using Amazon AWS EKS πŸ“” πŸ”œ
Installation Cloud Deployment: Deploying Malcolm Using AWS EC2 with AMI πŸ“” πŸ”œ
Configuration Configuring Malcolm πŸ“” πŸ“” πŸ”œ
Configuration Authentication and User Management πŸ“” πŸ”œ
Configuration Running Malcolm πŸ“” πŸ”œ
Configuration Ingesting Traffic: Capturing Live Network Traffic for Analysis πŸ“” πŸ”œ
Configuration Ingesting Traffic: Uploading PCAP for Analysis πŸ“” πŸ”œ
Configuration Sensor Placement πŸ”œ πŸ”œ
Configuration Using a Remote OpenSearch or Elasticearch Instance πŸ“” πŸ”œ
Configuration Managing OpenSearch/Elasticsearch Indexes πŸ“” πŸ“” πŸ”œ
Dashboards OpenSearch Dashboards Overview πŸ“” πŸ““ πŸ“Ό
Dashboards Pre-Built Dashboards πŸ“” πŸ”œ
Dashboards Queries and Filters πŸ“” πŸ”œ
Dashboards Notices and Signatures πŸ”œ πŸ”œ
Dashboards Discover πŸ“” πŸ”œ
Dashboards Anomaly Detection πŸ“” πŸ”œ
Dashboards Creating Custom Dashboards πŸ“” πŸ”œ
Dashboards Alerting: Configuring Email for Alerting πŸ“” πŸ”œ
Dashboards Alerting: Alerting πŸ“” πŸ”œ
Arkime Arkime Overview πŸ“” πŸ““ πŸ“Ό
Arkime Queries and Filters πŸ“” πŸ”œ
Arkime Sessions πŸ“” πŸ”œ
Arkime SPIView πŸ“” πŸ”œ
Arkime SPIGraph πŸ“” πŸ”œ
Arkime Connections πŸ“” πŸ”œ
Arkime Hunt πŸ“” πŸ”œ
Arkime CyberChef πŸ“” πŸ““ πŸ”œ
NetBox NetBox Overview πŸ“” πŸ““ πŸ“Ό
NetBox Manual Inventory Population πŸ“” πŸ”œ
NetBox Automatic Inventory Population πŸ“” πŸ”œ
NetBox Asset Interaction Analysis πŸ“” πŸ”œ
NetBox Backing up and Restoring the NetBox Inventory πŸ“” πŸ”œ
Analysis Pivoting Between Data Sources πŸ“” πŸ”œ
Analysis File Extraction and Analysis πŸ“” πŸ”œ
Analysis Severity Scoring πŸ“” πŸ”œ
Integrations Forwarding Third-Party Logs to Malcolm πŸ“” πŸ”œ
Integrations Using Threat Intelligence Feeds πŸ“” πŸ”œ
Other Log Enrichment πŸ”œ πŸ”œ
Configuration Using Custom Rules and Scripts πŸ“” πŸ”œ
Other Using the Malcolm REST API πŸ“” πŸ”œ
Hedgehog Linux Installing Hedgehog Linux πŸ“” πŸ“” πŸ”œ
Hedgehog Linux Configuring Hedgehog Linux πŸ“” πŸ”œ
Hedgehog Linux Operation: Running Hedgehog Linux πŸ“” πŸ”œ
Hedgehog Linux Operation: Monitoring Sensor Metrics πŸ”œ πŸ”œ
Clone this wiki locally