Zeek Agent is an endpoint monitoring tool for Linux and macOS that reports file, socket, and process events to Zeek. It captures event data from Linux Audit using the Unix domain socket plugin and from macOS using Endpoint Security framework. Collected event data is stored in an SQL database and later fetched by Zeek using scheduled queries. It can also interface to osquery for accessing endpoint information. Pre-built packages are available on the releases page. The Zeek Agent Framework provides API access to Zeek Agents and default scripts for recording endpoint activity into Zeek logs.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A static analysis framework for extracting key characteristics from various file formats
Comprehensive endpoint protection solution providing advanced threat detection, proactive defense, and efficient management.
Sangfor Technologies is a leading cybersecurity, cloud, and infrastructure vendor providing effective cybersecurity and efficient enterprise cloud solutions.
Endpoint security solution for businesses with advanced threat protection and management
Open-source tool for monitoring macOS hosts with detailed system activity insights.
Android Loadable Kernel Modules for reversing and debugging on controlled systems/emulators.
Cisco Secure Endpoint is a cloud-native endpoint security solution that provides advanced protection and response to threats.
A lightweight malware detection and removal tool that provides real-time protection against complex attacks while preserving system resources.
Microsoft Defender for Endpoint is a comprehensive endpoint security solution that provides industry-leading, multi-platform detection and response capabilities.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.