diff --git a/CHANGES b/CHANGES index da3a04bc18..990a840f50 100644 --- a/CHANGES +++ b/CHANGES @@ -1,4 +1,9 @@ +2.6-624 | 2019-07-16 16:07:59 +0000 + + * Redo README. We now have separate plain text and Markdown versions. + (Zeke Medley, Corelight) + 2.6-616 | 2019-07-16 15:21:37 +0000 * Fix referecne counting bug in EnumType copy constructor. (Jon diff --git a/README b/README index 2c71e11c0b..1dbad2ce1f 100644 --- a/README +++ b/README @@ -1,36 +1,93 @@ -============================= -Zeek Network Security Monitor -============================= +================================= +The Zeek Network Security Monitor +================================= -Zeek is a powerful framework for network analysis and security -monitoring. +Zeek is a powerful framework for network traffic analysis and security +monitoring. Follow us on Twitter at @zeekurity. -(Zeek is the new name for the long-established Bro system. Note that -parts of the system retain the "Bro" name, and it also often appears in -the documentation and distributions.) +Key Features +============ -Please see the INSTALL file for installation instructions and pointers -for getting started. NEWS contains release notes for the current -version, and CHANGES has the complete history of changes. Please see -COPYING for licensing information. +* **In-depth Analysis** + Zeek ships with analyzers for many protocols, enabling + high-level semantic analysis at the application layer. -You can download source and binary releases on: +* **Adaptable & Flexible** + Zeek's domain specific scripting language enables site-specific + monitoring policies and means that it is not restricted to any + particular detection approach. - https://www.zeek.org/download +* **Efficient** + Zeek targets high-performance networks and is used operationally + at a variety of large sites. -To get the current development version, clone our master git -repository: +* **Highly Stateful** + Zeek keeps extensive application-layer state about the network + it monitors and provides a high-level archive of a network's + activity. - git clone --recursive https://github.com/zeek/zeek +Getting Started +=============== -For more documentation, research publications, and community contact -information, please see the home page: +The best place to find information about getting started with Zeek is +our web site https://www.zeek.org, specifically the documentation +section there [1]. One the web site you can also get downloads for +stable releases, tutorials on getting Zeek set up, and many other +useful resources. - https://www.zeek.org +You can find release notes in NEWS, and a complete record of all +changes in CHANGES. -On behalf of the Zeek Development Team, +To work with the most recent code from the development branch of Zeek, +clone the master git repository: + + > git clone --recursive https://github.com/zeek/zeek + +With all dependencies [2] in place, build and install: + + > ./configure && make && sudo make install + +Write your first Zeek script: + + # File "hello.zeek" + + event zeek_init + { + print "Hello, World!"; + } + +And run it: + + > zeek hello.zeek + +For learning more about the Zeek scripting language, +https://try.zeek.org is a great resource. + +Development +=========== + +Zeek is developed on GitHub by its community. We welcome +contributions. Working on an open source project like Zeek can be an +incredibly rewarding experience and, packet by packet, makes the +Internet a little safer. Today, as a result of countless +contributions, Zeek is used operationally around the world by major +companies and educational and scientific institutions alike for +securing their cyber infrastructure. + +If you're interested in getting involved, we collect feature requests +and issues on GitHub. More information on Zeek's development can be +found here [2], and information about its community and mailing lists +(which are fairly active) can be found here [3]. + +License +------- + +Zeek comes with a BSD license, allowing for free use with virtually no +restrictions. You can find it in COPYING. + + +[1] https://www.zeek.org/documentation/index.html +[2] https://docs.zeek.org/en/stable/install/install.html +[3] https://www.zeek.org/development/index.html +[4] https://www.zeek.org/community/index.html -Vern Paxson & Robin Sommer, -International Computer Science Institute & -Lawrence Berkeley National Laboratory -vern@icir.org / robin@icir.org diff --git a/README.md b/README.md new file mode 100644 index 0000000000..5a39d327d4 --- /dev/null +++ b/README.md @@ -0,0 +1,108 @@ +