Skip to content

Add MMS protocol support via DINA community Zeek plugins#906

Open
maikbrueggemann wants to merge 3 commits intocisagov:mainfrom
maikbrueggemann:Integrate-MMS
Open

Add MMS protocol support via DINA community Zeek plugins#906
maikbrueggemann wants to merge 3 commits intocisagov:mainfrom
maikbrueggemann:Integrate-MMS

Conversation

@maikbrueggemann
Copy link
Copy Markdown

Integrates Manufacturing Message Specification (MMS) protocol analysis into Malcolm. MMS is the underlying protocol for TASE.2/ICCP, which is widely used in energy sector control systems for inter-control-center communications. Protocol parsing is handled by Zeek plugins from the DINA community project.

Changes include:

  1. Zeek plugins for MMS protocol parsing
  2. Logstash pipeline configuration to forward Zeek-generated MMS logs to OpenSearch
  3. OpenSearch dashboard for viewing and exploring MMS events

Testing:
Verified against captured MMS/TASE.2 network traffic replayed from pcap files.

Maik Brueggemann added 3 commits February 24, 2026 08:27
Integrate Manufacturing Message Specification (MMS) protocol analysis
into Malcolm by incorporating Zeek plugins from the DINA community
project (https://github.com/DINA-community).
@mmguero mmguero added zeek Relating to Malcolm's use of Zeek logstash Relating to Malcolm's use of Logstash labels Feb 25, 2026
@mmguero mmguero self-assigned this Feb 25, 2026
@mmguero mmguero added this to Malcolm Feb 25, 2026
@mmguero mmguero moved this to Review in Malcolm Feb 25, 2026
@mmguero mmguero modified the milestones: v26.04.0, v26.03.0 Feb 25, 2026
@mmguero mmguero modified the milestones: v26.03.0, v26.04.0 Mar 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

logstash Relating to Malcolm's use of Logstash zeek Relating to Malcolm's use of Zeek

Projects

Status: Review

Development

Successfully merging this pull request may close these issues.

2 participants