Zeek

zeek.org
Zeek Icon

Zeek (formally Bro) Passively monitors network traffic and looks for suspicious activity.

Open Source

Zeek Source Code

Author

zeek

Description

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

#bro#dfir#network-monitoring#nsm#pcap#security#zeek

Homepage

https://www.zeek.org

License

NOASSERTION

Created

06 Jul 12

Last Updated

17 Jan 25

Latest version

v7.2.0-dev

Primary Language

C++

Size

181,534 KB

Stars

6,582

Forks

1,231

Watchers

6,582

Language Usage

Language Usage

Star History

Star History

Recent Commits

  • zeek-bot (17 Jan 25)

    Update doc submodule [nomail] [skip ci]

  • zeek-bot (15 Jan 25)

    Update doc submodule [nomail] [skip ci]

  • Arne Welzel (14 Jan 25)

    Merge remote-tracking branch 'origin/topic/awelzel/fix-writer-info-in-logging-hooks' * origin/topic/awelzel/fix-writer-info-in-logging-hooks: logging: Fix reporter message logging: Avoid repeated writer name lookups for plugin hooks logging: Fix HookLogInit() and HookLogWrite() info usage

  • Benjamin Bannier (14 Jan 25)

    Merge branch 'topic/bbannier/coverity'

  • Benjamin Bannier (14 Jan 25)

    Bump auxil/spicy to latest development snapshot

  • Benjamin Bannier (14 Jan 25)

    Prevent unneeded copies in QUIC C++ helper code

  • Johanna Amann (14 Jan 25)

    Merge remote-tracking branch 'origin/topic/johanna/gh-4061' * origin/topic/johanna/gh-4061: Update BiF-tracking, add is_event_handled Address review comments and small updates for DNS warnings Raise warnings when for DNS events that are not raised due to dns_skip_all_addl

  • Arne Welzel (14 Jan 25)

    Merge remote-tracking branch 'origin/topic/vern/C++-standalone-record-redef' * origin/topic/vern/C++-standalone-record-redef: support for record extensions when using -O gen-standalone-C++

  • Vern Paxson (10 Jan 25)

    support for record extensions when using -O gen-standalone-C++

  • Arne Welzel (14 Jan 25)

    logging: Fix reporter message

  • Arne Welzel (14 Jan 25)

    logging: Avoid repeated writer name lookups for plugin hooks If a plugin provides a write hook, the invocation for HookLogWrite() would redo looking up the writer's name from the enum value and instantiating a new std::string instance for every write. Avoid doing this.

  • Arne Welzel (14 Jan 25)

    logging: Fix HookLogInit() and HookLogWrite() info usage There's two instances of WriterBackend::WriterInfo for a given writer. One in Manager::WriterInfo that's accessible via stream.writers and a copy within WriterFrontend. Commit 78999d147d7a98a064d25854eea38468c1af7c5e switched to use the address of the frontend's info instance for HookLogWrite() invocations, breaking users using the address for identification purposes.

  • Johanna Amann (08 Jan 25)

    Update BiF-tracking, add is_event_handled

  • Johanna Amann (08 Jan 25)

    Address review comments and small updates for DNS warnings This commit addresses review feedback for DH-4155. Furthermore it fixes test failures, and adds a new test for the is_event_handled bif.

  • Benjamin Bannier (14 Jan 25)

    Merge branch 'topic/bbannier/coverity'

  • Benjamin Bannier (13 Jan 25)

    Bump auxil/spicy to latest development snapshot

  • Benjamin Bannier (13 Jan 25)

    Prevent copies in various places

  • Tim Wojtulewicz (13 Jan 25)

    Merge remote-tracking branch 'origin/topic/bbannier/fix-spicy-ssl-includes' * origin/topic/bbannier/fix-spicy-ssl-includes: Fix incomplete includes in Spicy SSL analyer C++ code

  • Tim Wojtulewicz (13 Jan 25)

    Merge branch 'topic/timw/add-security-md' * topic/timw/add-security-md: Add SECURITY.md, pointing at the website

  • Tim Wojtulewicz (10 Jan 25)

    Add SECURITY.md, pointing at the website

  • Tim Wojtulewicz (13 Jan 25)

    Merge remote-tracking branch 'origin/topic/timw/non-routeable-subnets' * origin/topic/timw/non-routeable-subnets: Update zeekctl submodule [nomail]

  • Tim Wojtulewicz (10 Jan 25)

    Update zeekctl submodule [nomail]

  • Benjamin Bannier (12 Jan 25)

    Fix incomplete includes in Spicy SSL analyer C++ code This appears to have been broken by feec451bcee7c459bc9a93e39ae18dc41515ac17.

  • zeek-bot (12 Jan 25)

    Update doc submodule [nomail] [skip ci]

  • Benjamin Bannier (11 Jan 25)

    Merge branch 'topic/bbannier/bump-spicy'

  • zeek-bot (11 Jan 25)

    Update doc submodule [nomail] [skip ci]

  • Christian Kreibich (10 Jan 25)

    Merge remote-tracking branch 'origin/topic/etyp/harden-flaky-test' * origin/topic/etyp/harden-flaky-test: Harden flaky test based on creating a file

  • Benjamin Bannier (09 Jan 25)

    Mark `swap` specialization `noexcept`

  • Benjamin Bannier (09 Jan 25)

    Clean up some includes

  • Benjamin Bannier (09 Jan 25)

    Prevent exception in `noexcept` function.

Zeek Website

Website

The Zeek Network Security Monitor

Zeek (formerly Bro) is the world’s leading platform for network security monitoring. Flexible, open source, and powered by defenders.

Redirects

Does not redirect

Security Checks

All 66 security checks passed

Server Details

  • IP Address 192.0.78.212
  • Location San Francisco, California, United States of America, NA
  • ISP Automattic Inc
  • ASN AS2635

Associated Countries

  • US

Saftey Score

Website marked as safe

100%

Blacklist Check

zeek.org was found on 0 blacklists

  • ThreatLog
  • OpenPhish
  • PhishTank
  • Phishing.Database
  • PhishStats
  • URLhaus
  • RPiList Not Serious
  • AntiSocial Blacklist
  • PhishFeed
  • NABP Not Recommended Sites
  • Spam404
  • CRDF
  • Artists Against 419
  • CERT Polska
  • PetScams
  • Suspicious Hosting IP
  • Phishunt
  • CoinBlockerLists
  • MetaMask EthPhishing
  • EtherScamDB
  • EtherAddressLookup
  • ViriBack C2 Tracker
  • Bambenek Consulting
  • Badbitcoin
  • SecureReload Phishing List
  • Fake Website Buster
  • TweetFeed
  • CryptoScamDB
  • StopGunScams
  • ThreatFox
  • PhishFort

Website Preview

Zeek Reviews

More Intrusion Detection

About the Data: Zeek

API

You can access Zeek's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/networking/intrusion-detection/zeek

The REST API is free, no-auth and CORS-enabled. To learn more, view the Swagger Docs or read the API Usage Guide.

About the Data

Beyond the user-submitted YAML you see above, we also augment each listing with additional data dynamically fetched from several sources. To learn more about where the rest of data included in this page comes from, and how it is computed, see the About the Data section of our About page.

Share Zeek

Help your friends compare Intrusion Detection, and pick privacy-respecting software and services.
Share Zeek and Awesome Privacy with your network!

View Intrusion Detection (5)