zeek
Here are 335 public repositories matching this topic...
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.
-
Updated
Sep 5, 2026 - Python
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
-
Updated
Aug 25, 2026 - Python
⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐
-
Updated
Jul 1, 2024 - Go
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations secure their infrastructure. LME Docs can be found at https://cisagov.github.io/lme-docs/docs/
-
Updated
May 22, 2026 - Shell
Slips, a free software behavioral Python intrusion prevention system (IDS/IPS) that uses machine learning to detect malicious behaviors in the network traffic. Stratosphere Laboratory, AIC, FEL, CVUT in Prague.
-
Updated
Sep 8, 2026 - Python
Tenzir is the data pipeline engine for security teams.
-
Updated
Sep 8, 2026 - C++
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
-
Updated
Jun 17, 2026 - Go
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
-
Updated
Aug 25, 2026 - Python
Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark
-
Updated
Jun 1, 2026 - Jupyter Notebook
Zeek-Formatted Threat Intelligence Feeds
-
Updated
Sep 8, 2026 - Zeek
🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.
-
Updated
Mar 17, 2023 - Python
DynamiteNSM is a free Network Security Monitor to enable network visibility and advanced cyber threat detection
-
Updated
May 23, 2023 - Python
🔍 AI-assisted threat-hunting workbench for SOC and DFIR analysts — turns raw PCAPs into actionable intel with a Zeek + tshark pipeline, C2/beacon detection, JA3 fingerprinting, MITRE ATT&CK mapping, OSINT enrichment, and multilingual reports from local or cloud LLMs.
-
Updated
Aug 13, 2026 - Python
Threat Hunting Toolkit is a Swiss Army knife for threat hunting, log processing, and security-focused data science
-
Updated
Sep 1, 2026 - Shell
Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings
-
Updated
Jul 12, 2021 - Zeek
Local-first threat hunting for the logs you already have: Zeek, Pi-hole, syslog or the systemd journal, CloudTrail. Every run names the technique behind each detector. No agent, no daemon, no black box - between grep and a SIEM.
-
Updated
Sep 5, 2026 - Python
Extract files from network traffic with Zeek.
-
Updated
Mar 17, 2020 - Zeek
Add this topic to your repo
To associate your repository with the zeek topic, visit your repo's landing page and select "manage topics."