Loading...
Zeek Agent is an endpoint monitoring tool for Linux and macOS that reports file, socket, and process events to Zeek. It captures event data from Linux Audit using the Unix domain socket plugin and from macOS using Endpoint Security framework. Collected event data is stored in an SQL database and later fetched by Zeek using scheduled queries. It can also interface to osquery for accessing endpoint information. Pre-built packages are available on the releases page. The Zeek Agent Framework provides API access to Zeek Agents and default scripts for recording endpoint activity into Zeek logs.
Common questions about Zeek Agent including features, pricing, alternatives, and user reviews.
Zeek Agent is An endpoint monitoring tool for Linux and macOS that reports file, socket, and process events to Zeek.. It is a Endpoint Security solution designed to help security teams with Linux, Mac Os.
Prevention-first EDR stopping zero-day attacks, ransomware, and fileless malware
EDR platform with EPP capabilities for endpoint threat detection and response
eBPF-based, AI-driven EDR for edge, containers, and critical infra.
Kernel-level runtime integrity verification using NSA-licensed technology.
Get strategic cybersecurity insights in your inbox