About this project
Maltrail is an open-source network traffic detection system that identifies communication with known malicious infrastructure and reports selected traffic anomalies. It matches domains, URLs, IP addresses, IP:port pairs, User-Agent values, JA3/JA4 TLS fingerprints, and certificate hashes observed on the network against a set of indicators called trails.
The project has two independently deployable components. A multithreaded Rust sensor uses libpcap to capture traffic, perform trail matching and heuristic analysis, and produce events. A Python server accepts events, stores them in daily logs, and provides an HTTP API and browser-based reporting interface. The sensor can write events locally, forward them to a remote Maltrail server, emit CEF over syslog, or send JSON to Logstash.
Trails are assembled from more than 3,000 bundled static files, 42 public-feed integrations, and optional operator-supplied indicators. The updater merges feeds, custom trails, static trails from a separate repository, and engine lists into a trail database, publishing updates atomically only after a successful build. A confidence score derived from feed agreement helps prioritize triage.
The reporting interface supports live updates over Server-Sent Events, field-aware search with selectors such as src:, dst:, port:, proto:, trail:, and sev:, retro hunting across retained logs, geographic views, per-threat triage status and notes, sensor status, saved views, and CSV/JSON export. Country and ASN enrichment uses RIPE lookups by the server, with a local fallback for offline operation.
Heuristics cover scanning, DNS exhaustion, DGA-like lookups, suspicious downloads, proxy probes, and suspicious User-Agent values. Deployment validation is available through maltrail-sensor -T, and optional Prometheus metrics can be enabled. Installation is supported through a shell installer verified on multiple Linux distributions, FreeBSD, NetBSD, OpenBSD, and macOS, as well as Docker Compose and manual source builds. Prebuilt sensor binaries are provided for Linux x86_64 and aarch64 (glibc and musl), macOS, FreeBSD, and Windows.
Maltrail is designed for indicator-based network monitoring. Its heuristic detections supplement trail matching but do not replace endpoint telemetry or a general-purpose intrusion prevention system.
Comments
0 Rating appears after 10 ratings
Sign in to join the discussion.