awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
zeek avatar

zeek/zeek

0
View on GitHub↗
www.zeek.org↗

Zeek

Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level semantic logs. It functions as an application protocol analyzer and network intrusion detection system designed to extract meaning from network traffic and monitor for malicious activity.

The system focuses on archiving network activity and maintaining historical records of application-layer state for forensic investigation and auditing. It utilizes a combination of modular protocol analyzers and customizable detection policies to perform deep semantic analysis of numerous application-layer protocols.

Its broader capabilities include network traffic analysis, network security monitoring, and the ability to define site-specific monitoring rules to detect threats and anomalies.

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Features

  • Network Security Monitoring - Monitors network traffic and detects malicious activity using customizable detection policies.
  • Network Activity Archiving - Maintains detailed historical records of network events and application state for forensic investigation and auditing.
  • Network Analysis - Provides a comprehensive framework for capturing, monitoring, and analyzing network traffic.
  • Modular Analyzers - Employs a set of pluggable analyzers that decode specific application-layer protocols into a common event format.
  • Event-Driven Scripting - Executes custom analysis logic by triggering scripts based on real-time network events.
  • Network Traffic Analyzers - Transforms raw network packets into high-level semantic logs for security monitoring.
  • Application-Layer Protocol Inspections - Performs deep semantic analysis of numerous application-layer protocols to extract meaning from traffic.
  • Network Intrusion Detection - Monitors network traffic for suspicious patterns and malicious activity using customizable policies.
  • Protocol - Maintains persistent internal tables that map network connections to their current protocol state.
  • Protocol State Machines - Tracks application-layer state over time to reconstruct high-level conversations from individual packets.
  • Packet-to-Log Pipelines - Converts raw binary network traffic into structured semantic logs through a multi-stage analysis pipeline.
  • Application Layer Protocol Dissectors - Functions as a system that reconstructs and decodes application-layer protocols from raw network traffic.
  • Network Activity Archiving - Maintains extensive application-layer state to provide a high-level historical record of all network activity.
  • Network Traffic Analysis - Converts raw network packets into high-level semantic logs to monitor application layer activity.
  • Custom Logic Extensions - Provides mechanisms to tailor monitoring behavior and log generation via a specialized scripting language.
  • Domain Specific Languages - Provides a specialized domain-specific language for defining network monitoring policies and behavior rules.
  • Monitoring Policies - Allows the definition of custom detection approaches and site-specific monitoring rules.
  • Infrastructure Monitoring - Network analysis framework.
  • Network Monitoring Tools - Network security monitoring and analysis tool.
  • Security and Compliance - Network analysis framework for security monitoring.
7,735 stele·1,371 fork-uri·C++·10 vizualizări

Istoric stele

Graficul istoricului de stele pentru zeek/zeekGraficul istoricului de stele pentru zeek/zeek

Alternative open-source pentru Zeek

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu Zeek.
  • stamparm/maltrailAvatar stamparm

    stamparm/maltrail

    8,498Vezi pe GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    Vezi pe GitHub↗8,498
  • oisf/suricataAvatar OISF

    OISF/suricata

    6,008Vezi pe GitHub↗

    Suricata is an open-source network intrusion detection and prevention engine that analyzes live network traffic in real-time to identify and alert on malicious activity. It operates as a rule-based threat detection system, matching traffic against user-defined signatures to detect known attack patterns and policy violations, and can be placed inline to actively block malicious packets before they reach their target. The engine inspects a wide range of application-layer protocols including HTTP, DNS, TLS, SMB, and MQTT, and supports high-performance packet capture through specialized hardware a

    Ccybersecurityidsintrusion-detection-system
    Vezi pe GitHub↗6,008
  • security-onion-solutions/securityonionAvatar Security-Onion-Solutions

    Security-Onion-Solutions/securityonion

    4,661Vezi pe GitHub↗

    Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive

    Shell
    Vezi pe GitHub↗4,661
  • wireshark/wiresharkAvatar wireshark

    wireshark/wireshark

    9,477Vezi pe GitHub↗

    Wireshark is a network protocol analyzer and traffic inspector used for capturing and inspecting network traffic. It functions as a packet capture tool that intercepts live data from network interfaces and a TCP/IP dissector that decodes network protocol layers to translate raw binary packets into human-readable fields. The system provides capabilities for protocol stream reconstruction, grouping related packets into cohesive conversations between endpoints. It also operates as a packet file converter, allowing for the reading, modification, and conversion of network capture files across vari

    Cpacket-capturestratosharktshark
    Vezi pe GitHub↗9,477
Vezi toate cele 30 alternative pentru Zeek→

Întrebări frecvente

Ce face zeek/zeek?

Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level semantic logs. It functions as an application protocol analyzer and network intrusion detection system designed to extract meaning from network traffic and monitor for malicious activity.

Care sunt principalele funcționalități ale zeek/zeek?

Principalele funcționalități ale zeek/zeek sunt: Network Security Monitoring, Network Activity Archiving, Network Analysis, Modular Analyzers, Event-Driven Scripting, Network Traffic Analyzers, Application-Layer Protocol Inspections, Network Intrusion Detection.

Care sunt câteva alternative open-source pentru zeek/zeek?

Alternativele open-source pentru zeek/zeek includ: stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network… oisf/suricata — Suricata is an open-source network intrusion detection and prevention engine that analyzes live network traffic in… security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It… wireshark/wireshark — Wireshark is a network protocol analyzer and traffic inspector used for capturing and inspecting network traffic. It… requestly/requestly. kubeshark/kubeshark — Kubeshark is a network observability platform designed for Kubernetes environments, functioning as an eBPF-powered…