Moloch is an open source packet capture and search system that allows analysts and responders to examine large network packet captures. By default, Moloch organizes the packet captures into the various sessions contained within the capture. Moloch can be utilized as a network monitoring system that can be leveraged through importing packets into the Elasticsearch infrastructure. From here, responders can examine network activity in near real time. Another method that Moloch can be leveraged through is loading offline packet captures for indexing.
Installation instructions for Moloch can be found at https://molo.ch/#download. Moloch can be installed on a variety of Linux desktop or server platforms. The server option provides larger ...