Zeek Newsletter - Issue 46 - December 2024

Welcome to the Zeek Newsletter.


In this Issue:

  • TL;DR
  • Development Updates
  • Zeek in the Community
  • Zeek in the Enterprise
  • Friends of Zeek
  • Upcoming Events
  • Zeek Package Updates
  • Get Involved

[TL;DR]

Zeek 7.1.0 is here! See Development Updates for details.

Zeek webinars continue. See Upcoming Events for details.

Registration is still open for the free two day Zeek workshop in Munich, Germany on 26-27 February 2025. Day 1 features technical presentations by the Zeek team and community. We’ll cover common use cases, recent releases, Zeek’s roadmap, and more. Day 2 offers optional, hands-on training by Zeek team members on Incident Response with Zeek and Writing Zeek Analyzers With Spicy. See this site for details:

https://zeek.org/workshop-muc-2025/


Development Updates

Zeek 7.1.0 is here! This is the new “feature release.”

https://zeek.org/get-zeek

https://download.zeek.org/zeek-7.1.0.tar.gz

See the release notes for details of the addressed bugs and security issues:

https://github.com/zeek/zeek/releases/tag/v7.1.0

Binary packages for the new releases will also be available shortly:

https://github.com/zeek/zeek/wiki/Binary-Packages

Python 3.9 is now required to run Zeek and all of its associated tooling. This may cause breakage in workflows.

Zeek 7.1.0 ships with Spicy 1.12.0.

https://github.com/zeek/spicy/releases/tag/v1.12.0

See the NEWS file

https://github.com/zeek/spicy/blob/v1.12.0/NEWS.rst

for a high-level summary.

See the CHANGES file

https://github.com/zeek/spicy/blob/v1.12.0/CHANGES

for a detailed list.

Zeek 7.0.x is now the current LTS release. 7.0.5, released 16 December, is the latest version.

https://download.zeek.org/zeek-7.0.5.tar.gz

https://github.com/zeek/zeek/releases/tag/v7.0.5

Binary packages for the new releases will also be available shortly:

https://github.com/zeek/zeek/wiki/Binary-Packages

The 6.x series is being retired but may get a final patch.

For more information on release cadence, see:

https://github.com/zeek/zeek/wiki/Release-Cadence


Zeek in the Community

Seth published a new version of Malcolm. Please see the project site for details:

https://malcolm.fyi/


Zeek in the Enterprise

The recording of the 11 December webinar, Zeek File Extraction and Automating Malware Analysis by Seth Grover, is live here:

https://www.youtube.com/watch?v=Bw__xplbx1o


Friends of Zeek

The Suricata project released version 7.0.8. Visit their site for details:

https://suricata.io/download/


Upcoming Events

The next Zeek webinar, Designing Logs in the Real World, by Steve Smoot, will take place on Wednesday, January 8th at 1 pm ET.

Register for free here:

https://us06web.zoom.us/webinar/register/WN_frarKCKgSE2n5dwCbEHAqQ

Another Zeek webinar, Pluggable Cluster Backends, by Arne Welzel, will take place on Wednesday 22 January at 1 pm ET.

Register for free here:

https://us06web.zoom.us/webinar/register/WN__CoPGGUNT-m7A9BzOsZI_Q

The next Training Group Call is 17 January at 12 noon ET. Here is the Zoom link:

<https://ESnet.zoom.us/j/6445948648>

Meeting ID: 644 594 8648

Passcode: Rockon!

The next Zeek Community Call is scheduled for 5 March at 1 pm ET. There is no need to register. Here is the Zoom link:

https://us06web.zoom.us/j/99882457331?pwd=WVZLRGtpbmx1V2FqSnlRT1FLRC9lQT09


Zeek Package Updates

Changes to packages are available via this search:

https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed

The https://packages.zeek.org site reported the last 5 updates as of 2 June:

1/7/25, 4:14 AM shodan-zeek

1/4/25, 11:47 PM wildcard-domain

1/4/25, 11:45 PM anomalous-dns

1/3/25, 9:42 PM zeek-kafka

1/2/25, 12:37 PM spicy-redis


Get Involved

If you have any comments or material for the newsletter please email news@zeek.org or join the #news Slack channel.

https://zeekorg.slack.com

Here is an invitation to the Slack channel:

https://join.slack.com/t/zeekorg/shared_invite/zt-12z1pjy93-zuVGuT1BF~yUJJvERxhp7g

Stay up to date by joining the Zeek Discourse:

https://community.zeek.org

Subscribe to our YouTube channel:

https://youtube.com/c/Zeekurity

Follow us on Mastodon:

https://infosec.exchange/@zeek

The old mailing list archives now redirect to this site:

https://community.zeek.org/archives/list/zeek@lists.zeek.org/

If you’d like to read the Leadership Team meeting notes, they are here:

https://github.com/zeek/zeek/wiki/LT-Meeting-Notes

Follow us on LinkedIn:

https://www.linkedin.com/company/zeekurity

To search LinkedIn for jobs mentioning Zeek skills, use this query:

<https://www.linkedin.com/jobs/search/?keywords=zeek>

See you next time!