Zeek Community

Dedicated to Zeek® for over 20 years.

Not only did the founders and engineers at Corelight build and extend Zeek over the last two decades, we continue to dedicate significant resources toward improving the platform. The rich structured and correlated data produced by Zeek is the result of hundreds of person-years of work by a dedicated group of developers and contributors, funded in part by the National Science Foundation and ICSI.

Vern Paxson - Zeek Inventor

Corelight was co-founded by Zeek’s inventor, Vern Paxson, and lead open-source Zeek developers, Robin Sommer and Seth Hall, to meet market demand for a commercial Zeek sensor.

Over the years Corelight's developers have made many important contributions to the project, including:

SMB analyzer

This protocol analyzer parses and generates Microsoft® and Server Message Block (SMB) related logs, giving users visibility into critical area of typical corporate network traffic related to events such as file sharing and printer access.

Kerberos analyzer

This protocol analyzer parses and generates logs related to the Kerberos network authentication protocol, which allows nodes in a network to authenticate and communicate over unsecured connections.

RADIUS analyzer

This protocol analyzer parses and generates logs related to the RADIUS authentication protocol, giving visibility into network events like user authentication attempts to access a corporate network.

Long connections script

This Zeek script gives incident responders early visibility into long-lived connections that would otherwise not be logged until the connection ends. It does this by generating a new Zeek log that reports intermediately on long connections.

Vern Paxson

Vern Paxson

Chief Scientist

Inventor of Zeek

Robin Sommer

Robin Sommer

CTO

Lead open-source Zeek developer

Seth Hall

Seth Hall

Chief Evangelist

Lead open-source Zeek developer

Corelight was created to take the complexity out of Zeek deployment. Our products are up and running in about 15 minutes on your network.

It’s hard to run open-source Zeek in an enterprise environment.

Zeek is a powerful framework, and as you’d expect with great power comes great…resource needs. From learning the Zeek framework to getting support and help when needed, open-source Zeek can be intense.

Corelight is Zeek made enterprise-ready.

Corelight Sensors are an out-of-band solution that are ready to integrate into your network architecture. Sensors come pre-loaded with Zeek packages, automatic updates, and are supported by the team who created Zeek and continues to work on the open-source platform.

Corelight makes Zeek easy.

Compare Corelight to an open-source deployment. Or, contact us to learn more about our products.

Corelight bro comparison

Get involved with the Zeek project. Start now at zeek.org.

  • Recent Zeek releases and scripts
  • Research in development
  • Tutorials and FAQs
  • Community boards
  • Videos
  • Events and meetups
Zeek / Bro project