Maltrail is a malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails, along with static trails compiled from various AV reports and custom user-defined lists, where trail can be anything from domain name, URL, IP address (e.g. 185.130.5.231 for the known attacker) or HTTP User-Agent header value (e.g. sqlmap for automatic SQL injection and database takeover tool). Also, it uses (optional) advanced heuristic mechanisms that can help in the discovery of unknown threats (e.g. new malware). Sensor(s) is a standalone component running on the monitoring node (e.g. Linux platform connected passively to the SPAN/mirroring port or transparently inline on a Linux bridge) or at the standalone machine (e.g. Honeypot) where it "monitors" the passing Traffic for blacklisted items/trails (i.e. domain names, URLs and/or IPs).

Features

  • Server's primary role is to store the event details and provide back-end support for the reporting web application
  • Server component can be skipped altogether
  • Fully functional demo pages with collected real-life threats
  • To properly run the Maltrail, Python 2.6, 2.7 or 3.x is required on nix/BSD system
  • Test the capturing of DNS traffic
  • Stop Sensor and Server instances

Project Samples

Project Activity

See All Activity >

License

MIT License

Follow Maltrail

Maltrail Web Site

Other Useful Business Software
Our Free Plans just got better! | Auth0 Icon
Our Free Plans just got better! | Auth0

With up to 25k MAUs and unlimited Okta connections, our Free Plan lets you focus on what you do best—building great apps.

You asked, we delivered! Auth0 is excited to expand our Free and Paid plans to include more options so you can focus on building, deploying, and scaling applications without having to worry about your security. Auth0 now, thank yourself later.
Try free now
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of Maltrail!

Additional Project Details

Operating Systems

Linux

Programming Language

Python

Related Categories

Python Security Software, Python Performance Testing Software

Registered

2022-02-03