11/12 free views
Framework
Framework
Network Security

zeek

by zeek

7.4Kstars
1.3Kforks
347watchers
Updated 3 months ago
About

Zeek is a powerful and flexible network analysis framework designed for in-depth network traffic monitoring and security event detection.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Primary Use Case

Zeek is primarily used for comprehensive network monitoring and intrusion detection by security teams at large organizations and research institutions. It enables detailed analysis of network protocols and activities, allowing users to implement custom detection policies through its scripting language. This makes it ideal for securing high-performance networks and automating security monitoring tasks.

Key Features
  • In-depth analysis with protocol-specific analyzers at the application layer
  • Adaptable and flexible through a domain-specific scripting language for custom monitoring policies
  • Efficient performance suitable for high-speed networks
  • Highly stateful tracking of network activity and application-layer state
  • Provides a high-level archive of network activity for forensic analysis

Installation

  • Clone the repository with all dependencies: git clone --recursive https://github.com/zeek/zeek
  • Ensure all prerequisites are installed as per the official documentation
  • Build and install Zeek using: ./configure && make && sudo make install

Usage

>_ zeek hello.zeek

Runs a Zeek script, in this example printing 'Hello World!'

Security Frameworks
Reconnaissance
Discovery
Collection
Detection
Command and Control
Usage Insights
  • Leverage Zeek's scripting language to create custom detection rules tailored to your network environment.
  • Integrate Zeek logs with SIEM platforms for enhanced correlation and alerting capabilities.
  • Use Zeek's high-fidelity network metadata to support forensic investigations and incident response.
  • Deploy Zeek in tandem with endpoint detection tools to provide comprehensive network and host visibility.
  • Automate threat hunting workflows by combining Zeek's output with machine learning analytics.

Docs Take 2 Hours. AI Takes 10 Seconds.

Ask anything about zeek. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.

3 free chats per tool • Instant responses • No credit card

Security Profile
Red Team70%
Blue Team90%
Purple Team85%
Details
LicenseOther
LanguageC++
Open Issues1705
Topics
bro
network-monitoring
pcap
security
nsm
dfir
zeek
ndr