Zeek
Zeek (formerly Bro) Network Security Monitor
Open-source network security monitor detecting intrusions, malware, and policy violations with logs for network forensics and analysis
What is Zeek?
Zeek (formerly known as Bro) is an open-source network security monitor designed to detect suspicious traffic patterns and activities on networks. Developed by the National Center for Supercomputing Applications, Zeek passively monitors network traffic in real-time and generates logs for further analysis.
Some key capabilities and features of Zeek include:
- Traffic analysis - Zeek can analyze all types of traffic including HTTP, DNS, SMTP, SSH etc. for signs of intrusions, malware infections, compromised hosts, and more.
- Event logging - Zeek logs contain detailed records of all the events and activities it detects on the network like connections, files transferred, authentication attempts etc.
- Policy monitoring - Custom policies can be created to trigger specific actions when defined traffic patterns occur on the network.
- Scalability - Zeek is highly scalable and can monitor networks with very high traffic volumes and bandwidth.
- Customization - Zeek's event engine allows users to develop custom scripts and plugins using languages like C++ and Python to extend functionality.
Zeek generates rich log files which contain transaction details and can be used for in-depth investigations and forensic analysis. It is commonly used to detect attacks, malware infections, suspicious insider activities, performance issues and policy violations on corporate networks.
Zeek Features
Features
- Real-time traffic analysis
- Protocol analysis
- Custom protocol detection
- Dynamic protocol detection
- File extraction
- Asset tracking
- Anomaly detection
- Signature-based detection
Pricing
- Open Source
Pros
Cons
Official Links
Reviews & Ratings
Login to ReviewThe Best Zeek Alternatives
View all Zeek alternatives with detailed comparison →
Top Security & Privacy and Network Monitoring and other similar apps like Zeek
Here are some alternatives to Zeek:
Suggest an alternative ❐Suricata
Snort
Arkime
LOKI Free IOC Scanner
Redborder
Maltrail