Zeek
Zeek, formerly known as Bro, is an open source network security monitoring tool that provides a powerful platform for network traffic analysis. In Chapter 6, we explained that it is included in the Malcolm suite of tools. Zeek passively monitors network packets. Then, it generates high-level logs that will contain the details of network activities. Zeek functions only as an IDS solution but don’t count it out. Not everyone finds IPS solutions to be beneficial to their business needs, so in that regard, Zeek might be the better solution for you or your organization. It is also designed to be highly flexible and customizable. Zeek allows users to create custom scripts and plugins to extend its functionality. It can also analyze network protocols, detect and log security incidents, and provide just as valuable insights into network behavior as Suricata. Keep in mind that all of this customization and extensibility comes at the price of more complicated setup routines.
Like...