218 results for “topic:zeek”
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
:star: :star: Distributed tcpdump for cloud native environments :star: :star:
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations secure their infrastructure. LME Docs can be found at https://cisagov.github.io/lme-docs/docs/
Slips, a free software behavioral Python intrusion prevention system (IDS/IPS) that uses machine learning to detect malicious behaviors in the network traffic. Stratosphere Laboratory, AIC, FEL, CVUT in Prague.
Tenzir is the data pipeline engine for security teams.
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
This project is a SIEM with SIRP and Threat Intel, all in one.
Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark
Zeek-Formatted Threat Intelligence Feeds
C++ parser generator for dissecting protocols & files.
🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.
DynamiteNSM is a free Network Security Monitor developed by Dynamite Analytics to enable network visibility and advanced cyber threat detection
Threat Hunting Toolkit is a Swiss Army knife for threat hunting, log processing, and security-focused data science
Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings
Extract files from network traffic with Zeek.
Zeek IDS Dockerfile
Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)
Open source endpoint agent providing host information to Zeek. [v2]
A completely automated anomaly detector Zeek network flows files (conn.log).
Collection of scripts, files, and tips to create and maintain networks, hack, and more!
Zeek's Messaging Library
Run zeek with zeekctl in docker
A Zeek Network Security Monitor tutorial that will cover the basics of creating a Zeek instance on your network in addition to all of the necessary hardware and setup and finally provide some examples of how you can use the power of Zeek to have absolute control over your network.
A Zeek script to generate features based on timing, volume and metadata for traffic classification.
A Zeek log writer plugin that publishes to Kafka.
Documentation for Zeek
Zeek (formerly Bro) Network Security Monitor package for pfSense router/firewall
Zeek network security monitor plugin that enables parsing of the Ethernet/IP and Common Industrial Protocol standards