Corelight Zeek
Open source network security monitoring tool for traffic analysis

Corelight Zeek Description
Zeek is an open source network security monitoring tool originally developed in the 1990s under the name "Bro" and renamed in 2018. The tool operates as a passive network analysis system that runs on sensors (hardware, software, virtual, or cloud-based) to analyze network traffic in real-time. Zeek functions differently from active defense mechanisms like firewalls or intrusion prevention systems. It captures and analyzes network activity to generate high-fidelity transaction logs, file contents, and customizable data outputs. The tool provides visibility into network communications by tracking network events and producing detailed log files. The platform is designed for manual review by security analysts or integration into SIEM systems for centralized security monitoring. Zeek offers extensibility through community-contributed packages and can be customized to meet specific monitoring requirements. The project has been federally funded for over 20 years and is currently supported by Corelight. Zeek has a deployment base of over 10,000 installations worldwide and maintains an active open source community that contributes to its development through code, documentation, and feature enhancements.
Corelight Zeek FAQ
Common questions about Corelight Zeek including features, pricing, alternatives, and user reviews.
Corelight Zeek is Open source network security monitoring tool for traffic analysis developed by Zeek. It is a Network Security solution designed to help security teams with Open Source, Zeek, Network Monitoring.
ALTERNATIVES
Network detection and response platform with IDS, NSM, and threat intel.
Zeek-based network traffic analysis & IDS platform for enterprise deployments.
A Zeek-based protocol analyzer that parses GQUIC traffic to extract connection metadata and create fingerprints for detecting anomalous network behavior.
An open source packet capture and forwarding tool that captures network packets on one machine and sends them to another for remote monitoring and analysis.
POPULAR
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox