Skip to content
  • There are no suggestions because the search field is empty.
PROTECTING OVER $1B IN DAILY TRADES
DEFENDING ENERGY FOR 32+M U.S. USERS
SECURING NETWORKS FOR 52K+ TRANSPORT VEHICLES
DEFENDING $10T+ IN MANAGED ASSETS
SECURING 16+M ANNUAL PATIENT VISITS
Home/Podcasts/Episode 23 - Inside Zeek 9:...
Episode 23 - Inside Zeek 9: Modernizing Open Source Network Monitoring & Agentic Security Scanning Podcast Episode Title Here
September 10, 2026

Episode 23 - Inside Zeek 9: Modernizing Open Source Network Monitoring & Agentic Security Scanning Podcast Episode Title Here

Episode 23 - Inside Zeek 9: Modernizing Open Source Network Monitoring & Agentic Security Scanning Podcast Episode Title Here
0:00 / 0:00

About the episode

In this episode, host Richard Bejtlich sits down with Christian Kreibich, Zeek's technical lead, to unpack the upcoming Zeek 9 release and what it means for practitioners. Christian explains how the project structures its three-releases-a-year cadence and how the team has spent recent cycles modernizing Zeek—including the shift to ZeroMQ for cluster messaging and new systemd-based cluster orchestration. A major thread is security: alongside longstanding fuzzing and static analysis work, the team is now navigating a wave of agentic, LLM-driven security scanning, with preliminary internal efforts surfacing 50–70 high-severity findings and parallel initiatives from OpenAI/Trail of Bits and Anthropic. The conversation also covers the migration from BinPAC to Spicy for safer protocol parsing, why the team favors Spicy over Rust for writing analyzers (while eyeing Rust elsewhere), the ongoing Microsoft Defender for Endpoint collaboration bringing Zeek to Windows, and a clear roadmap toward cloud-native packet ingestion, better tunnel handling, and a simpler packaging ecosystem. It's a grounded look at how a mature open source project stays modern without breaking what works.

Episode transcript

Transcript coming soon...