Zeek Blog
Zeek 3.2 Release Candidate Available—and Zeek 3.1.5 and Zeek 3.0.8 as well
We are very happy to make a first release candidate of Zeek 3.2 available today. Barring any unforeseen issues, the final 3.2 release should be out in about two weeks from now. We highlight some updates in 3.2 below. Please see NEWS for full release notes, and CHANGES...
Zeek Package Contest – ZPC-3
Update: added winners and Jury members. Are you a Zeek user?Do you enjoy writing Zeek scripts? Do you like being recognized for your awesome work? Do you want to make the world’s networks safer? Do you like winning prizes and claiming...
Zeek Monthly Newsletter – Issue 6 – July 2020
Issue 6 - July 2020 Welcome to the Zeek Monthly Newsletter! Issue 6 covers June 2020 as well as upcoming events. In this Issue: TL;DR Development UpdatesZeek BlogZeek In The CommunityNew Zeek PackagesZeek in EnterpriseUpcoming EventsZeek Related...
Zeek Monthly Newsletter – Issue 5 – June 2020
Issue 5 - June 2020 Welcome to the Zeek Monthly Newsletter, Issue 5 covers May 2020 as well as upcoming events. In this Issue: TL;DR Development UpdatesZeek BlogZeek In The CommunityNew Zeek Related PackagesZeek in EnterpriseUpcoming EventsZeek Related...
Zeek From Home – Episode 6 – Zeek Scripting 101 to 495 in 45 Mins. – Recording Now Available!
Zeek From Home, Episode 6 recorded on 10 June and featured guest Aashish Sharma of LBL and the Zeek Project Leadership Team who discussed and presented on Zeek Scripting. Zeek From Home is a weekly Zeek Webinar series where Zeek users, developers and...
Zeek Package Contest – ZPC-2 – Winners Announced!
We are thrilled to announce the winners of our second Zeek Package Contest. ZPC-2 (Zeek Package Contest Number 2) was announced on 6 April 2020 and concluded on 15 May. The focus of this competition was on the MITRE ATT&CK™ Framework, more...
Zeek From Home – Episode 5 – Brim Security – Recording Now Available!
Zeek From Home, Episode 5 recorded on 3 June and featured guests Phil Rzewski, Technical Director and Steve McCanne, Coding CEO at Brim Security who discussed and presented on Brim’s recent open source app and more. To learn more check the recording.
Zeek From Home – Episode 4 – Security Onion (Part 1) – Recording Now Available!
Zeek From Home – Episode 4 – Security Onion – Recording Now Available!
7 Dos And Don’ts For Zeek Scripting
This post serves as an introduction to some of the pitfalls I had to learn about whilst writing scripts. Hopefully, they help you avoid the same pitfalls. In some of the below example code snippets, bold font is used to emphasize a particular pitfall. If you’d like to...
Zeek From Home – Episode 3- Suricata
Zeek From Home, Episode 3 recorded on 20 May featured guests Victor Julien, OISF Founder and Suricata's Lead Developer and Josh Stroschein, Ph.D., Director of Training and Academic Initiatives who discussed and presented on Suricata. Zeek From Home is a weekly...
Announcing the (New) Spicy Parser Generator
We are very happy to announce a new Zeek project now available on GitHub. The Spicy parser generator makes it substantially easier for Zeek to support and parse new protocols and file formats. I will tell you a bit more about Spicy’s capabilities and history in the...
Zeek From Home – Episode 2- Looking Deeper into the Zeek 3.0 – Major Changes, Point Releases and more – Recording Now Available!
We kicked off the Zeek From Home May series with a Zeek 3.0 presentation from Tim Wojtulewicz of Corelight. You can find out more about upcoming Zeek webinars on the zeek.org events calendar. Latest Zeek From Home Webinar 13 May - Zeek 3.0 - Major Changes,...
Zeek Monthly Newsletter – Issue 4 – May 2020
Issue 4 - May 2020 Welcome to the Zeek Monthly Newsletter, Issue 4 covers April 2020 as well as upcoming events. In this Issue: General Community News/UpdatesDevelopment UpdatesZeek in the NewsZeek In, Near and Around the CommunityInterviews/Blog...
People of Zeek – Interview Series – Phil Rzewski of Brim Security
In our continuing People of Zeek interview series, today we have Phil Rzewski, Technical Director at Brim Security and active Zeek community member. Phil, thank you so much for taking time out of your schedule to answer a few questions and let the community get to...
People of Zeek Interview Series – Matthias Vallentin of Tenzir
In our continuing People of Zeek interview series, today we have Matthias Vallentin, Co-Founder and CEO of Tenzir as well as an active Zeek community member. Matthias, thank you so much for taking time out of your schedule to answer a few questions and let the...
Zeek From Home – Episode 1 – Zeek-Agent – Recording Now Available
Last week we announced our Zeek From Home series and on Wednesday 15 April we kicked off the series with a presentation by Seth Hall on the new Zeek Agent. You can find out more about upcoming Zeek webinars on the zeek.org events calendar. Latest Zeek From...
Writing My First Protocol Analyzer
I recently tried my hand at writing my first protocol analyzer for Zeek. This is something that I’ve wanted to accomplish since first learning about Zeek. I recall trying to concatenate all the strings from tcp_contents() and parse application layer data using string...
Got Zoom ?
I still find it amazing what you can find quite simply with Zeek. Since Zoom seems to be on top of mind for many recently, as an example to show how easily you can highlight specific traffic with great accuracy and granularity, I wrote this simple PoC package...
Zeek Monthly Newsletter – Issue 3 – April 2020
Issue 3 - April 2020 Welcome to the Zeek Monthly Newsletter, Issue 3 covers March 2020 as well as upcoming events. In this Issue: General Community News/UpdatesDevelopment UpdatesZeek in the NewsZeek In the CommunityInterviews Threat of the MonthUpcoming...
Zeek Package Contest – ZPC-2
Are you a Zeek user?Do you enjoy writing Zeek scripts? Do you like being recognized for your awesome work? Do you want to make the world’s networks safer? Do you like winning prizes and claiming bragging rights?Do you want the...
2019 Zeek Package Contest Summary & Winners
In late 2019, we held the first Zeek Package Contest (ZPC-1) and announced the winners at ZeekWeek. For those who may have missed this contest or may not have been at ZeekWeek in Seattle this blog post is a summary of the contest and the contributions. For ZPC-1...
The New IO Loop in Zeek 3.1
Zeek has a long-standing issue with standby CPU usage on low-power systems and low-traffic networks where even if nothing is happening on the network, Zeek will continue to use 10-15% of the CPU doing nothing. This stems from the fact that the existing main loop of...
Zeek From Home
Since we won’t be holding any in-person Zeek events for the foreseeable future, we’d like to invite you to be part of a new weekly ‘Zeek From Home’ webinar series to kick off in April. The schedule will be announced once we have a few submissions queued up. These...
ZeekWeek 2020 Austin – Cancelled – Open Letter to the Community
Dear Zeek Community, It is our hope that all of you are staying safe and healthy during this uncertain time. We’re all navigating unfamiliar territory together, as the COVID 19 crisis affects every aspect of our lives both personally and...
People of Zeek Interview Series – Keith Lehigh of Indiana University and the Zeek Leadership Team
In our continuing People of Zeek interview series, today we have Keith Lehigh, Chair of the Open Source Zeek Leadership Team (LT). Keith thank you so much for taking time out of your schedule to answer a few questions and let the community get to know more about you....
People of Zeek Interview Series – Doug Burks of Security Onion
In our continuing People of Zeek interview series, today we have Doug Burks, Founder of Security Onion and CEO of Security Onion Solutions. Doug, thank you so much for taking time out of your schedule to answer a few questions and let the community get to know more...
Announcing the Zeek Agent
This posting is cross-posted between the Zeek blog and the Trail of Bits blog. Announcing The Zeek Agent The Zeek Network Security Monitor provides a powerful open-source platform for network traffic analysis. However, from its network vantage point, Zeek...
Announcing the NEW Zeek Website!
In 2018, Vern Paxson, Zeek creator, announced that the Bro Project had officially changed its name from “Bro” to “Zeek”. With a new project name comes new branding, and in 2019 in the opening remarks for ZeekWeek the new Zeek Project logo was announced. And today we...
Zeek Slack Channel Announced
You’re Invited!! We’re so excited to announce the NEW Zeek Slack workspace: zeekorg.slack.comAlong with this new Slack workspace we are also introducing a Code of Conduct and Slack Channel Guidelines. We’ve adopted modified versions of the Kubernetes Community Code of...
Zeek Monthly Newsletter, Issue 2 – March 2020
Welcome to the Zeek Monthly Newsletter, Issue 2 covers January and February 2020 as well as upcoming events. In this Issue: General Community News/Updates Development Updates Zeek In the Community Threat of the Month Upcoming Events Contribution/Contributor of...
RSS - Posts