Zeek Agent
An endpoint monitoring tool for Linux and macOS that reports file, socket, and process events to Zeek.

Zeek Agent
An endpoint monitoring tool for Linux and macOS that reports file, socket, and process events to Zeek.
Zeek Agent Description
Zeek Agent is an endpoint monitoring tool for Linux and macOS that reports file, socket, and process events to Zeek. It captures event data from Linux Audit using the Unix domain socket plugin and from macOS using Endpoint Security framework. Collected event data is stored in an SQL database and later fetched by Zeek using scheduled queries. It can also interface to osquery for accessing endpoint information. Pre-built packages are available on the releases page. The Zeek Agent Framework provides API access to Zeek Agents and default scripts for recording endpoint activity into Zeek logs.
Zeek Agent FAQ
Common questions about Zeek Agent including features, pricing, alternatives, and user reviews.
Zeek Agent is An endpoint monitoring tool for Linux and macOS that reports file, socket, and process events to Zeek.. It is a Endpoint Security solution designed to help security teams with Linux, Mac Os.