Zeek turns raw packets into tidy, queryable logs โ conn.log, dns.log, http.log. It's the difference between drowning in packets and answering questions with grep.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Instant protocol-structured telemetry from any capture.
zeek-cut extracts columns โ your jq-for-logs.
Patterns pop fast in structured logs.
Encrypted โ invisible: metadata fingerprints sessions.
Zeek's event-driven scripting = programmable NSM.
| -r pcap | offline analyze |
| zeek-cut | column extractor |
| conn/dns/http | core logs |
| notice.log | zeek's alerts |
| local.zeek | your scripts |
Logs from Zeek feed Splunk/Elastic beautifully โ pipeline practice.
PCAPs from CyberDefenders are perfect zeek-gym material.
Critical Stack/BZAR packages add ATT&CK-flavored detections free.
Terminology note: Zeek WAS Bro โ old tutorials use the old name.
Use Zeek (Bro) only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.