
Episode 23 - Inside Zeek 9: Modernizing Open Source Network Monitoring & Agentic Security Scanning Podcast Episode Title Here
Corelight DefeNDRs
• 22 min
Play episode
In this episode, host Richard Bejtlich sits down with Christian Kreibich, Zeek's technical lead, to unpack the upcoming Zeek 9 release and what it means for practitioners. Christian explains how the project structures its three-releases-a-year cadence and how the team has spent recent cycles modernizing Zeek—including the shift to ZeroMQ for cluster messaging and new systemd-based cluster orchestration. A major thread is security: alongside longstanding fuzzing and static analysis work, the team is now navigating a wave of agentic, LLM-driven security scanning, with preliminary internal efforts surfacing 50–70 high-severity findings and parallel initiatives from OpenAI/Trail of Bits and Anthropic. The conversation also covers the migration from BinPAC to Spicy for safer protocol parsing, why the team favors Spicy over Rust for writing analyzers (while eyeing Rust elsewhere), the ongoing Microsoft Defender for Endpoint collaboration bringing Zeek to Windows, and a clear roadmap toward cloud-native packet ingestion, better tunnel handling, and a simpler packaging ecosystem. It's a grounded look at how a mature open source project stays modern without breaking what works.
Loading
