Integration With Firewall/IPS for Autonomous Response #912
-
|
Does Malcolm have any capability to integrate with an existing firewall or IPS for autonomous response to malicious traffic, or is it purely a detection/analysis platform? From the docs it appears to be the latter. Thanks. |
Beta Was this translation helpful? Give feedback.
Answered by
mmguero
Mar 3, 2026
Replies: 1 comment 1 reply
-
|
Malcolm is passive by design and is not configured by default to be able to perform actions in response to what it observes. However some possibilities to achieve what you're talking about (I haven't done this, exactly, so take it with a grain of salt) might involve:
Best of luck. |
Beta Was this translation helpful? Give feedback.
1 reply
Answer selected by
alasdairmuckart
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Malcolm is passive by design and is not configured by default to be able to perform actions in response to what it observes.
However some possibilities to achieve what you're talking about (I haven't done this, exactly, so take it with a grain of salt) might involve: