
Top picks: Corelight Open NDR Platform, GQUIC Protocol Analyzer, Netis Cloud Probe — plus 45 more compared.
Network SecurityEvaluating Corelight Zeek alternatives comes down to matching Network Security capabilities to your environment, integrations, and budget rather than chasing feature parity. The options below are compared on what actually drives a switch: coverage, deployment fit, pricing, and real reviews from security teams. Independent and vendor-neutral: we never sell rankings.
Corelight Zeek is a free Network Detection and Response tool developed by Corelight. Security professionals most commonly compare it with Corelight Open NDR Platform, GQUIC Protocol Analyzer, Netis Cloud Probe, Apache Spot (Incubating), and Stamus Networks Clear NDR. All 48 alternatives are matched by shared capabilities, tags, and NIST CSF 2.0 coverage.
A closer look at the 8 most relevant alternatives and competitors to Corelight Zeek, including their key features and shared capabilities.
Network detection and response platform with IDS, NSM, and threat intel.
A Zeek-based protocol analyzer that parses GQUIC traffic to extract connection metadata and create fingerprints for detecting anomalous network behavior.
An open source packet capture and forwarding tool that captures network packets on one machine and sends them to another for remote monitoring and analysis.
Apache Spot is an open source big data platform that analyzes network flows and packet data to identify security threats and provide visibility into enterprise computing environments.
Network detection and response platform for threat detection and analysis
Digital experience monitoring for network, device, and app performance
Flow-based network traffic monitoring and bandwidth analysis tool
Network traffic broker for visibility, monitoring, and traffic optimization
Network detection and response platform with IDS, NSM, and threat intel.
A Zeek-based protocol analyzer that parses GQUIC traffic to extract connection metadata and create fingerprints for detecting anomalous network behavior.
An open source packet capture and forwarding tool that captures network packets on one machine and sends them to another for remote monitoring and analysis.
Apache Spot is an open source big data platform that analyzes network flows and packet data to identify security threats and provide visibility into enterprise computing environments.
Network detection and response platform for threat detection and analysis
Digital experience monitoring for network, device, and app performance
Flow-based network traffic monitoring and bandwidth analysis tool
Network traffic broker for visibility, monitoring, and traffic optimization
Network traffic analysis tool for real-time intrusion detection and monitoring
Qualified network TAPs for traffic duplication and network monitoring
Network Detection and Response system for threat detection and response
Real-time network security monitoring for threat detection using DPI and sandbox
SaaS-based NDR platform for threat investigation and Tier 1 workflows
TLS/SSL decryption for network traffic visibility and security analysis
Flow-based network monitoring platform for performance and security visibility
Network visibility and security insights platform for IT environments
DNS-layer network visibility and monitoring with query logging and analytics
TLS decryption solution that extracts session keys from memory for traffic inspection
Modular network observability platform for packet brokering, capture & analytics.
Packet-based network observability platform for hybrid environments.
Polish NDR appliance for network threat detection, forensics & GDPR compliance.
Passive network intelligence platform for gov/defense with real-time visibility.
Flow load balancer for distributing & filtering NetFlow records to collectors.
Network intelligence platform for detecting, and responding to security incidents
Network security monitoring platform with IDS, PCAP capture, and asset discovery.
Enterprise network monitoring via deep packet inspection & traffic classification.
Flow-based network security monitoring tool using anomaly detection.
Network defense platform with real-time content inspection & threat blocking
Autonomous AI-powered NDR platform using a proprietary LLM for SOC automation.
Protocol-layer network fingerprinting suite for bot, proxy & malware detection.
DDI platform with DNS security, DHCP, and IPAM for enterprise networks.
AI-driven network security platform for MSPs serving SMBs.
Passive copper TAP range for non-intrusive Ethernet traffic monitoring.
Bypass TAP/packet broker hybrid for before-and-after inline tool traffic analysis.
Managed NDR solution delivering network threat hunting via passive traffic metadata.
Network monitoring and detection solution for threat analysis
Arkime is an open-source network capture and analysis tool that provides comprehensive network visibility, facilitating swift identification and resolution of security and network issues.
NetFlow/IPFIX traffic analyzer for network visibility and anomaly detection.
Open source framework for network traffic analysis with advanced features.
Passive Network Audit Framework (PNAF) v0.1.2 provides passive network auditing capabilities and is now a project of COSMIC-Chapter of The Honeynet Project.
Zeek Remote desktop fingerprinting script for fingerprinting Remote Desktop clients.
High-performance packet capture library with zero copy functionality.
Makes output from the tcpdump program easier to read and parse.
NDR solution providing network visibility, threat detection, and intrusion prevention
NDR platform for IT/OT environments with threat detection and CTI
Security controller for policy mgmt, orchestration & log management
AI-powered threat detection platform using self-supervised learning for NDR
NDR platform with NGIPS, NetFlow/sFlow analysis, SIEM, and correlation engine
Common questions security professionals ask when evaluating alternatives and competitors to Corelight Zeek.
The most popular alternatives to Corelight Zeek include Corelight Open NDR Platform, GQUIC Protocol Analyzer, Netis Cloud Probe, Apache Spot (Incubating), and Stamus Networks Clear NDR. These Network Detection and Response tools offer similar capabilities and are frequently compared by security professionals evaluating their options.
There are 48 alternatives to Corelight Zeek listed on CybersecTools, all within the Network Detection and Response category. Each alternative is matched based on shared capabilities, tags, and NIST CSF coverage areas.
Corelight Zeek is a free Network Detection and Response tool. You can use it at no cost. Both free and commercial alternatives are available for comparison.
Corelight Zeek is a Network Detection and Response tool within the broader Network Security category. It is used by security professionals for network detection and response capabilities and can be compared against 48 similar tools.