Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
maltrail — Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS, HTTP, and IP traffic. | Kitploit
Tools/GitHubGitHub/stamparm/maltrail
Defensive ToolsIndicator of Compromise (IOC) ManagementThreat Feeds & AggregatorsNetwork ForensicsInformation GatheringNetwork SecurityMalware AnalysisThreat IntelligenceIntrusion DetectionAnti-BotEmail SecurityDNS Analysis
8.6k1.3k1656h 25m agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Anomaly Detection
Log Analysis
Top in Anomaly Detection #18
Top in Anti-Bot #18
Top in Email Security #15
Top in Intrusion Detection #8
Top in Indicator of Compromise (IOC) Management #15
Top in Log Analysis #19
Top in Network Forensics #18
Top in Threat Feeds & Aggregators #12
Top in Threat Intelligence #10
GitHubstamparm/maltrail

maltrail

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS, HTTP, and IP traffic.

View Repository
Share

Maltrail

License Sensor Server Trails X

Maltrail

Maltrail is a network traffic detection system that identifies communication with known malicious infrastructure and reports selected traffic anomalies. It matches domains, URLs, IP addresses, IP:port pairs, and User-Agent values observed on the network against a set of indicators called trails.

A detection is recorded as a single event containing the source, destination, protocol, matched trail, classification, and trail source:

"2026-08-07 09:14:22.117034" gw 10.13.13.2 57809 1.1.1.1 53 UDP DNS malware.bakewithdavid.com "asyncrat (malware)" (static)

Maltrail is designed for indicator-based network monitoring. Its heuristic detections supplement trail matching, but it is not a replacement for endpoint telemetry or a general-purpose intrusion prevention system.

Features

  • A full trail build combining more than 3,000 bundled static files, 42 public-feed integrations, and optional operator-supplied trails.
  • A multithreaded Rust sensor using libpcap, with optional Linux PACKET_FANOUT capture workers.
  • A Python server providing the reporting interface, event intake, and HTTP API.
  • Plain-text custom trails and whitelists that can be reviewed and version-controlled.
  • Heuristics for scanning, DNS exhaustion, DGA-like lookups, suspicious downloads, proxy probes, suspicious User-Agent values, and related network activity.
  • Local event logging, remote Maltrail logging, CEF over syslog, and Logstash JSON output.
  • Deployment validation with maltrail-sensor -T and optional Prometheus metrics.

Contents

  • Architecture
  • Reporting interface
  • Performance
  • Installation
    • Installer
    • Building from source
    • Systemd
    • Docker
  • Configuration
  • Trails
  • Events and API
  • Operations
    • Monitoring
    • Event retention
  • Documentation
  • Contributing
  • Project
    • License
    • Maintainers
    • Sponsors
    • Presentations and publications
    • Derived blacklist
    • Third-party integrations
    • Acknowledgements

Architecture

Maltrail consists of two independent processes that may run on the same host or on separate hosts:

   ┌──────────┐   events (UDP or file)   ┌──────────┐
   │  sensor  │ ───────────────────────► │  server  │ ◄── browser
   └──────────┘                          └──────────┘
    Rust                                  Python
    libpcap + PACKET_FANOUT               reporting UI + API
    trail matching + heuristics

The sensor captures traffic, performs trail matching and heuristic analysis, and produces events. It can write events locally (LOG_DIR), send them to a remote Maltrail server (LOG_SERVER), or do both. It can also emit CEF over syslog (SYSLOG_SERVER) and JSON to Logstash (LOGSTASH_SERVER).

The server receives and stores remote events, serves locally available event logs, and provides the web interface and API.

Reporting interface

Maltrail includes a browser-based reporting interface for exploring detected traffic, with live updates, field-aware search, retro hunting, geographic views, triage, saved views and export.

Maltrail reporting interface

The interface is served by server.py at HTTP_ADDRESS:HTTP_PORT. It is plain JavaScript with a single third-party runtime dependency (PapaParse, for CSV parsing) and no build step. One day is viewed at a time, selected with a date picker that doubles as an event-density grid over the available daily logs. Events are streamed from /events and aggregated in the browser into threats — one row per distinct (source, trail) — shown in a sortable grid with a detail panel.

FeatureNotes
Live modeAppended events are pushed over Server-Sent Events (/live) and merged into the current view. Falls back to polling byte ranges of the daily log when SSE is unavailable, or for sessions the stream cannot serve. New high-severity threats can raise a desktop notification and an audible alert; both can be muted
SearchField-scoped tokens (src: dst: port: proto: type: trail: info: family: tag: uid: sev: dir: status:; family:interlock pulls in interlock-1/-2, the shards one feed dump arrives split into) combined with space as AND, - to exclude, * wildcards, CIDR (src:10.0.0.0/8), and numeric ranges and comparisons (port:>1024, count:>=100). Active filters appear as removable chips
Retro huntSearches all retained daily logs for one indicator (/hunt), not just the day in view. Bounded by a day limit, a wall-clock budget and a sample cap; a day the budget cut short is reported separately from the completed days rather than counted as a finished total. A per-day sidecar index (LOG_DIR/index/, USE_EVENT_INDEX) lets the sweep skip every non-matching line and makes /counts exact
World mapPer-country event density for the selected day (/geo), placing the external endpoint of each event. Events that cannot be attributed to an external address are reported as unmapped rather than guessed. Set HOME_LAT / HOME_LON to draw origin arcs
TriagePer-threat status (new / investigating / resolved / false positive), free-text notes, tags, and hiding. Whitelist rules and OSINT pivots are available from the row context menu
Saved viewsNamed filter presets
ExportThe current filtered view as CSV, JSON, or defanged indicators
AppearanceDark and light themes, and discrete text-size steps

Triage state, saved views, tags and appearance settings are stored in the browser (localStorage), not on the server: they are per-browser and per-origin, and are not shared between analysts.

Sessions restricted with a network filter see only events from their own networks, and that restriction applies to the counts, map and blacklist endpoints as well as to the event list.

Country and ASN enrichment for individual addresses is looked up at stat.ripe.net by the server, which caches the results and serves them to the interface from its own /ripe endpoint; the browser talks to nothing but Maltrail. Set DISABLE_RIPE_LOOKUPS to switch the outbound lookups off entirely. Without them — or on a host with no internet access — flags come from the local RIR table instead and everything else in the interface works offline.

Performance

Performance depends on processor, traffic composition, trail-set size, capture driver, and network interface. The figures below measure the sensor's packet-processing path in isolation; they are not end-to-end live-capture measurements.

Representative measurements on an AMD Ryzen 7 PRO 4750U with heuristics enabled and a 1.5 million-row trail set:

TrafficTime per packet
ICMP echo, 58 bytes101 ns
TCP SYN, 70 bytes302 ns
Bulk TLS, 1,473 bytes402 ns
DNS query with a warm cache, 93 bytes452 ns
Mixed traffic, 866-byte average552 ns
HTTP request, 169 bytes602 ns
DNS query with a unique name, 93 bytes1,102 ns
Download Tool