← Back to match
Maltrail
Network traffic detection system that flags communication with known malicious infrastructure
PlatformWebfree
Maltrail is an open-source network traffic detection system that identifies communication with known malicious infrastructure by matching domains, URLs, IPs, and User-Agent values against a large database of threat indicators, supplemented by heuristics for anomalies like DNS exhaustion or DGA-like lookups. It combines a Rust packet-capture sensor with a Python reporting server and HTTP API. It is aimed at network security teams that want indicator-based detection alongside their existing endpoint and intrusion-prevention tools.
Categories
Network SecurityThreat DetectionIntrusion Detection

