
Zeek
Zeek is a free open-source network security monitor that passively analyses traffic into rich logs for detection, forensics and SIEM workflows.
0 upvotes · 0 downvotes
No ratings yet
- Category
- Defensive Security & Monitoring
- Pricing
- Free
- Platforms
- LinuxmacOS
- License
- Open source
- Reviewed
- Last reviewed 2 October 2026
What it is
Zeek is a free open-source network security monitor (formerly Bro) maintained by the Zeek Project (zeek.org). It passively inspects live or captured traffic and emits detailed, structured logs about connections and application-layer protocols rather than acting as an inline IPS.
What it helps with
- Generating high-fidelity network transaction logs for HTTP, DNS, TLS, SSH and many other protocols.
- Supporting network security monitoring, hunting and incident investigations beside packet tools such as Wireshark.
- Feeding SIEM and detection pipelines with consistent, scriptable telemetry.
- Extending analysis with Zeek scripts and community packages for site-specific detection logic.
- Assisting forensics and compliance reviews with durable records of who talked to whom and what was transferred.
- Running on sensors across Linux and other supported platforms without a commercial licence for the core software.
Who it's for
SOC analysts, detection engineers and network defenders who need an open NSM foundation as a peer to Suricata-style IDS and commercial network analytics.
Worth knowing
Zeek is free and open source. Official site and documentation: zeek.org and docs.zeek.org. Distinct from signature IDS engines such as Suricata or Snort; many teams run Zeek alongside them. Confirm current release channels on the project download pages.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.