Inspired by a video by Erik Hjelmvik, in this episode of Zeek in Action Richard installs the Brim NSM console within a Windows 10 sandbox. This process enables safer analysis of captured traffic. The idea is to add another layer of separation between a potentially vulnerable traffic processing tool and the underlying analysis operating system. The approach applies to other NSM tools as well. Do you use methods like this? Let us know in the comments below.