zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Github星跟踪图

Zeek Logo

The Zeek Network Security Monitor

A powerful framework for network
traffic analysis and security monitoring.

Key Features
Documentation
Getting Started
Development
License

Follow us on Twitter at @zeekurity.

Key Features

  • In-depth Analysis
    Zeek ships with analyzers for many protocols, enabling high-level semantic
    analysis at the application layer.

  • Adaptable and Flexible
    Zeek's domain-specific scripting language enables site-specific monitoring
    policies and means that it is not restricted to any particular detection
    approach.

  • Efficient
    Zeek targets high-performance networks and is used operationally at a variety
    of large sites.

  • Highly Stateful
    Zeek keeps extensive application-layer state about the network it monitors
    and provides a high-level archive of a network's activity.

Getting Started

The best place to find information about getting started with Zeek is
our web site www.zeek.org, specifically the
documentation section
there. On the web site you can also find downloads for stable
releases, tutorials on getting Zeek set up, and many other useful
resources.

You can find release notes in NEWS,
and a complete record of all changes in CHANGES.

To work with the most recent code from the development branch of Zeek,
clone the master git repository:

git clone --recursive https://github.com/zeek/zeek

With all dependencies
in place, build and install:

./configure && make && sudo make install

Write your first Zeek script:

# File "hello.zeek"

event zeek_init()
    {
    print "Hello World!";
    }

And run it:

zeek hello.zeek

For learning more about the Zeek scripting
language, try.zeek.org is a great resource.

Development

Zeek is developed on GitHub by its community. We welcome
contributions. Working on an open source project like Zeek can be an
incredibly rewarding experience and, packet by packet, makes the
Internet a little safer. Today, as a result of countless
contributions, Zeek is used operationally around the world by major
companies and educational and scientific institutions alike for
securing their cyber infrastructure.

If you're interested in getting involved, we collect feature requests
and issues on GitHub here and
you might find
these
to be a good place to get started. More information on Zeek's
development can be found
here, and information
about its community and mailing lists (which are fairly active) can be
found here.

License

Zeek comes with a BSD license, allowing for free use with virtually no
restrictions. You can find it here.

主要指标

概览
名称与所有者zeek/zeek
主编程语言C++
编程语言Makefile (语言数: 13)
平台
许可证Other
所有者活动
创建于2012-07-06 20:30:16
推送于2025-06-05 12:57:56
最后一次提交2025-06-05 07:15:59
发布数187
最新版本名称v7.2.1 (发布于 2025-05-20 09:31:01)
第一版名称v1.6-dev (发布于 2011-01-15 15:25:12)
用户参与
星数6.9k
关注者数353
派生数1.3k
提交数18.5k
已启用问题?
问题数1563
打开的问题数183
拉请求数2404
打开的拉请求数14
关闭的拉请求数358
项目设置
已启用Wiki?
已存档?
是复刻?
已锁定?
是镜像?
是私有?