SoCruel.NU

The domain that loves BSD

Home About Me Archive Contact

Zeek on FreeBSD series

Zeek is a network security monitoring platform which generates rich network metadata. Zeek is not an active security device. It sits on a sensor, a hardware, software, virtual, or cloud platform that quietly and unobtrusively observes network traffic. Zeek interprets what it sees and creates compact, high-fidelity transaction logs, file content, and fully customized output - rich network metadata. This metadata is very valuable for general network troubleshooting, getting insight in what happens on your network, and even for incident response and forensics!

See below the links to all the Zeek based blog posts.

The series

The series consists of the following posts:

Resources

Some (other) resources about this subject:

Updated: March 9, 2021