Skip to content

Could Malcolm identify and display operating systems? #538

Closed Answered by mmguero
meetpity asked this question in Q&A
Discussion options

You must be logged in to vote

Hi! Here are my thoughts on your questoins.

  1. Sort of, but not directly. All of the information Malcolm has comes from passive observing of network traffic. It's not querying or probing any endpoints in the network, so anything it knows it has to glean from communications between endpoints and/or the internet. Your best bet, probably, is to check out the Software dashboard in Dashboards and see what comes up there. There are some Zeek scripts (such as this one) that are enabled which will attempt to detect user agents that may indicate, for example, what version of Microsoft Windows is detected.
  2. That's interesting... is the rest of your data, other logs besides the DNS logs, showing up in …

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by mmguero
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #535 on December 19, 2024 14:50.