Skip to content

Zeek (Formerly Bro)

Definition

An open-source network analysis framework that processes live traffic or PCAP files and produces structured per-session log files covering DNS, HTTP, SSL, file transfers, and connection metadata. Zeek does not store raw packets, making it better suited to high-volume monitoring than interactive packet inspection.

Type
Open-source network analysis framework
Input
Live traffic or PCAP files
Output
Structured per-session log files
Logs cover
DNS, HTTP, SSL, file transfers, connections
Limitation
Does not store raw packets

Common questions

Why would an investigator use Zeek instead of a packet-capture tool like Wireshark?+

Zeek converts raw traffic into structured, searchable session logs summarising protocol-level activity across potentially huge volumes of traffic, which scales to continuous high-volume monitoring far better than manually inspecting packets, while Wireshark suits detailed inspection of an already-narrowed set of packets.

What is the practical consequence of Zeek not storing raw packets?+

Because Zeek discards packets after logging their summarised metadata, an examiner cannot go back later and extract full packet content, such as file bytes or exact payloads, from Zeek logs alone, so a parallel full packet capture is still needed when byte-level evidence may be required.

Related terms

Device Profile
A vendor-maintained database entry describing how to communicate with a specific make, model, and firmware version of a mobile device. The profile...
Logical Extraction
NIST SP 800-101 R1 Level 2 acquisition. Uses the OS-exposed backup APIs (Android ADB backup, iOS iTunes/Finder backup, MTP for media) to...
NIST CFTT
The National Institute of Standards and Technology Computer Forensics Tool Testing programme. It publishes independent test reports for digital forensic tools, including...
PCAP File
A packet capture file storing raw network frames in the libpcap format. PCAP files are the standard exchange format between network forensic...
Physical Extraction
An acquisition method that reads the raw storage medium, producing a bit-for-bit image from which allocated and deleted data can both be...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.