Zeekurity Zen Zeries
Zeek (formerly named Bro) is my favorite network security monitoring platform, and I’ve used and promoted it throughout my career. It generates rich network metadata that’s incredibly valuable for incident response, forensics, and general troubleshooting.
For most people, the main challenge with using Zeek is in setting it up. While today there exists Corelight (an easy-to-use Zeek appliance with enterprise support), not everyone has the budget for this. Plus, it’s fun to do it yourself and learn a thing or two. 😉
This series will walkthrough Zeek setup and a variety of tips and tricks I’ve learned over the years.
- Part I: How to Install Zeek (Bro) on CentOS 8
- Part II: Zeek Package Manager
- Part III: How to Send Zeek (Bro) Logs to Splunk