Description
Zeek (formerly Bro) is an open-source network security monitor that parses live or PCAP traffic into a rich log format covering DNS, HTTP, TLS, SSH, files, and notices. It is heavily used in network DFIR.
Inputs
Tool Chain
Tools that can use this tool's outputs as inputs
outputs
IOC (Indicator of Compromise)
inputs into
outputs
DNS Records
inputs into
Reviews
0.0 (0 reviews)