No description
Find a file
Johanna Amann 83a1165675 Merge remote-tracking branch 'origin/master' into topic/johanna/spicy-tls
* origin/master: (352 commits)
  Bump Spicy.
  Remove support for old Spicy versions from QUIC analyzer.
  Make sure that vcpkg isn't preferred if pcap_root_dir is passed in
  Remove some unused Spicy state.
  Bump Spicy.
  ZAM fix for concretizing vectors in record constructors
  improve ZAM's estimation of profiling overheads
  CI: Remove commented openssl 1.1 workaround from macOS preparation script
  CI: Fix installation of python package on macOS
  Address review feedback for configure error change
  Raise configure error message for unsupported archives
  fix ZAM "cat" of doubles/times to include trailing ".0" per normal BiF behavior
  CI: Specify the xcode version of the macOS Sonoma instance
  Remove vestigial Conan bit in CMakeLists.txt
  When configuring Spicy, be prepated for zeek_lib or zeek_exe targets.
  Fix a typo in CMakeLists.txt when building Zeek as a library
  Bump Spicy to current `main`.
  tie into updates to gen-zam
  ZAM documentation updated to reflect finer-grained profiling
  ZAM-specific BTest baseline changes for tweak to how ZAM bodies print
  ...
2024-04-16 08:08:16 +01:00
.github/workflows github/generate-docs: Only commit if there are staged changes 2024-03-18 09:35:28 +01:00
auxil Bump Spicy. 2024-04-15 17:25:12 +02:00
ci Merge remote-tracking branch 'origin/master' into topic/johanna/spicy-tls 2024-04-16 08:08:16 +01:00
cmake@1d793368ac Make sure that vcpkg isn't preferred if pcap_root_dir is passed in 2024-04-11 15:25:49 -07:00
cmake_templates framework for --enable-ZAM-profiling configuration 2024-03-19 10:59:49 -07:00
doc@126bdb2250 Make sure that vcpkg isn't preferred if pcap_root_dir is passed in 2024-04-11 15:25:49 -07:00
docker Add jq to final.Dockerfile 2023-11-21 22:23:37 +09:00
man Use the same rules as cmake submodule to reformat Zeek 2023-05-09 08:31:43 -07:00
scripts spicy/zeekygen: Remove mtime from generated code 2024-02-27 15:06:02 +01:00
src Merge remote-tracking branch 'origin/master' into topic/johanna/spicy-tls 2024-04-16 08:08:16 +01:00
testing ZAM-specific BTest baseline changes for tweak to how ZAM bodies print 2024-03-19 10:59:49 -07:00
.cirrus.yml CI: Specify the xcode version of the macOS Sonoma instance 2024-03-28 12:45:39 -07:00
.clang-format Format JSON with clang-format 2023-10-30 09:41:13 +01:00
.clang-tidy Disable annoying bugprone-easily-swappable-parameters clang-tidy check [skip ci] 2022-10-07 16:15:47 -07:00
.cmake-format.json Format JSON with clang-format 2023-10-30 09:41:13 +01:00
.dockerignore Add .dockerignore to suppress btest artifacts 2021-09-24 17:04:26 -07:00
.git-blame-ignore-revs Update .git-blame-ignore-revs 2023-10-30 09:42:39 +01:00
.gitattributes GH-1497: Support CRLF line-endings in Zeek scripts and signature files 2021-04-08 20:32:30 -07:00
.gitignore Update .gitignore to add Emacs and Vim temp files 2024-02-07 12:12:58 -07:00
.gitmodules highwayhash: Point to github.com/google/highwayhash, bump to master 2024-03-05 18:01:39 +01:00
.pre-commit-config.yaml Format JSON with clang-format 2023-10-30 09:41:13 +01:00
.style.yapf Format Python scripts with yapf. 2021-11-24 23:13:24 +01:00
.typos.toml retention of superseded AST elements to prevent pointer mis-aliasing 2023-11-10 11:06:16 +01:00
.update-changes.cfg Add script to update external test repo commit pointers 2019-04-05 17:09:01 -07:00
CHANGES Merge remote-tracking branch 'origin/topic/robin/bump-spicy' 2024-04-15 17:53:26 +02:00
CMakeLists.txt Make sure that vcpkg isn't preferred if pcap_root_dir is passed in 2024-04-11 15:25:49 -07:00
configure Address review feedback for configure error change 2024-04-02 16:49:43 +01:00
COPYING Update COPYING to 2023 2023-01-03 12:10:03 -07:00
COPYING-3rdparty Rename COPYING.3rdparty to COPYING-3rdparty 2023-01-03 12:10:03 -07:00
INSTALL Update documentation to include "Book of Zeek" revisions 2021-02-01 15:54:36 -08:00
Makefile Fix usage of realpath on macOS, instead preferring grealpath 2023-06-13 15:51:47 -07:00
NEWS Add community contributions for the 6.2 timeframe to NEWS. [skip ci] 2024-03-12 20:19:52 -07:00
README Add tooling section to README 2023-01-27 13:03:52 -07:00
README.md Update link to slack in README.md 2023-06-01 14:21:44 +02:00
vcpkg.json Switch all of the conan configuration to vcpkg 2024-02-02 14:52:16 -07:00
VERSION Merge remote-tracking branch 'origin/topic/robin/bump-spicy' 2024-04-15 17:53:26 +02:00
zeek-path-dev.in Move CMake template files to separate directory 2023-06-26 13:39:59 -07:00

Zeek Logo

The Zeek Network Security Monitor

A powerful framework for network traffic analysis and security monitoring.

Key FeaturesDocumentationGetting StartedDevelopmentLicense

Follow us on Twitter at @zeekurity.

Coverage Status Build Status

Slack Discourse

Key Features

  • In-depth Analysis Zeek ships with analyzers for many protocols, enabling high-level semantic analysis at the application layer.

  • Adaptable and Flexible Zeek's domain-specific scripting language enables site-specific monitoring policies and means that it is not restricted to any particular detection approach.

  • Efficient Zeek targets high-performance networks and is used operationally at a variety of large sites.

  • Highly Stateful Zeek keeps extensive application-layer state about the network it monitors and provides a high-level archive of a network's activity.

Getting Started

The best place to find information about getting started with Zeek is our web site www.zeek.org, specifically the documentation section there. On the web site you can also find downloads for stable releases, tutorials on getting Zeek set up, and many other useful resources.

You can find release notes in NEWS, and a complete record of all changes in CHANGES.

To work with the most recent code from the development branch of Zeek, clone the master git repository:

git clone --recursive https://github.com/zeek/zeek

With all dependencies in place, build and install:

./configure && make && sudo make install

Write your first Zeek script:

# File "hello.zeek"

event zeek_init()
    {
    print "Hello World!";
    }

And run it:

zeek hello.zeek

For learning more about the Zeek scripting language, try.zeek.org is a great resource.

Development

Zeek is developed on GitHub by its community. We welcome contributions. Working on an open source project like Zeek can be an incredibly rewarding experience and, packet by packet, makes the Internet a little safer. Today, as a result of countless contributions, Zeek is used operationally around the world by major companies and educational and scientific institutions alike for securing their cyber infrastructure.

If you're interested in getting involved, we collect feature requests and issues on GitHub here and you might find these to be a good place to get started. More information on Zeek's development can be found here, and information about its community and mailing lists (which are fairly active) can be found here.

License

Zeek comes with a BSD license, allowing for free use with virtually no restrictions. You can find it here.

Tooling

We use the following tooling to help discover issues to fix, amongst a number of others.