Zeek Newsletter - Issue 39 - May 2024

Welcome to the Zeek Newsletter.


In this Issue:

  • TL;DR
  • Development Updates
  • Zeek in the Community
  • Zeek in the Enterprise
  • Friends of Zeek
  • Upcoming Events
  • Zeek Package Updates
  • Get Involved

TL;DR

ZeekWeek 2024 will be held on 13-14 August at the Caltech Ramo Auditorium 2 located in Pasadena, California. The CFP is still open and tickets are on sale. Additionally there will be a Zeek training event on 15 August. See later in the newsletter for details.


Development Updates

On 14 May Benjamin published Spicy 1.10.1, 1.9.1 and 1.8.4. These are bugfix releases for the versions of Spicy which are bundled with Zeek. Please see this post for details:

https://community.zeek.org/t/spicy-bugfix-releases-1-10-1-1-9-1-and-1-8-4/7357

On 16 May Tim published Zeek Zeek 6.0.4 and 6.2.1. These are bugfix releases. Please see this post for details:

https://community.zeek.org/t/zeek-bugfix-releases-6-0-4-and-6-2-1/


Zeek in the Community

On 30 May Seth published a new version of Malcolm. Please see the project site for details:

https://malcolm.fyi/

On 30 May Doug published Security Onion 2.4.70, which includes Zeek 6.0.4. Congratulations to Doug and the SO team for their 15 year birthday on 4 June!

https://blog.securityonion.net/2024/05/security-onion-2470-now-available.html


Zeek in the Enterprise

Corelight is hiring a remote open source developer to work on Zeek. See this job description for details:

https://boards.greenhouse.io/corelight/jobs/5796333


Friends of Zeek

On 23 April, the Suricata project released versions 7.0.5 and 6.0.19. Visit their site for details:

https://suricata.io/download/


Upcoming Events

The next Zeek Community Call is 5 June at 1 pm ET. There is no need to register. Here is the Zoom link:

https://us06web.zoom.us/j/99882457331?pwd=WVZLRGtpbmx1V2FqSnlRT1FLRC9lQT09

ZeekWeek 2024 will be held on 13-14 August at the Caltech Ramo Auditorium 2 located in Pasadena, California. Additionally there will be a Zeek training event on 15 August. ZeekWeek will be an in-person event. Presentations will be recorded and published afterwards.

You can register here:

https://zeek.org/zeekweek2024/registration/

The call for papers for ZeekWeek 2024 is now live.

https://zeek.org/zeekweek2024/call-for-presentations/

Abstracts for talk submissions must be submitted by 14 June. Final notifications will be sent by 1 July. Talks will be reviewed in several rounds before the final submission deadline. Earlier submissions have a higher chance of acceptance. You will be notified as soon as a decision has been made on your talk.

Please see this post for details:

https://community.zeek.org/t/zeekweek-2024-call-for-presentations/

On 2 April, Seth posted to the Zeek Slack that DHS CISA will host a two day Malcolm-focused conference (MalCON) near Arlington, VA on 4-5 September. There will also likely be a virtual option. The event will likely include training for Malcolm, enterprise traffic analysis, and perhaps OT/ICS traffic analysis. If you would like to know more, contact Seth Grover in the Zeek Slack.

The next Security Onion conference will be held 4 October in Augusta, GA. The CFP is open. Please see this post for details:

https://blog.securityonion.net/2024/04/security-onion-conference-2024-save.html


Zeek Package Updates

Changes to packages are available via this search:

https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed

The https://packages.zeek.org site reported the last 5 updates as of 2 June:

6/4/24, 4:14 AM shodan-zeek

6/3/24, 3:01 PM zeekjs-redis

5/30/24, 6:56 PM zeek-plugin-tds

5/30/24, 6:55 PM zeek-plugin-s7comm

5/30/24, 6:55 PM zeek-plugin-enip


Get Involved

If you have any comments or material for the newsletter please email news@zeek.org or join the #news Slack channel.

https://zeekorg.slack.com

The Slack channel has been active during the past month. Here is an invitation link:

https://join.slack.com/t/zeekorg/shared_invite/zt-12z1pjy93-zuVGuT1BF~yUJJvERxhp7g

Stay up to date by joining the Zeek Discourse:

https://community.zeek.org

Subscribe to our YouTube channel:

https://youtube.com/c/Zeekurity

Follow us on Twitter:

https://twitter.com/Zeekurity

Follow us on Mastodon:

https://infosec.exchange/@zeek

The old mailing list archives now redirect to this site:

https://community.zeek.org/archives/list/zeek@lists.zeek.org/

If you’d like to read the Leadership Team meeting notes, they are here:

https://github.com/zeek/zeek/wiki/LT-Meeting-Notes

Follow us on LinkedIn:

https://www.linkedin.com/company/zeekurity

To search LinkedIn for jobs mentioning Zeek skills, use this query:

https://www.linkedin.com/jobs/search/?&keywords=zeek

See you next time!