Zeek
Zeek
Zeek (Netzwerk-Monitor)
Zeek is an open-source network security monitor that does not primarily search traffic for signatures but translates it into rich, structured logs — who communicated with whom, when, over which protocol. These metadata are the basis for analysis, threat hunting and network forensics. Zeek is designed for large networks and continuous operation.
History & facts. Zeek (formerly Bro) pursues a different approach from a classic IDS: instead of only reacting to known attack patterns, it generates detailed, searchable logs from the traffic, and its own scripting language allows tailored evaluations. This creates a permanent, context-rich representation of network activity that can also be examined retrospectively.
Outlook & recommendation. The metadata generated by Zeek are especially valuable because they remain meaningful even when content is encrypted — connection patterns, frequencies and counterparts reveal much. Combined with Suricata (signature detection) and central evaluation, a powerful network observation (NDR/NSM) emerges, which NEOSEC deploys precisely where endpoint agents are not possible — such as in OT and medical IT environments. The prerequisite remains that the logs are retained centrally and for a sufficiently long time.