Zeek Newsletter - Issue 47 - January 2025

Welcome to the Zeek Newsletter.


In this Issue:

  • TL;DR
  • Development Updates
  • Zeek in the Community
  • Zeek in the Enterprise
  • Friends of Zeek
  • Upcoming Events
  • Zeek Package Updates
  • Get Involved

[TL;DR]

Zeek webinars continue. See Upcoming Events for details.

Registration is still open for the free two day Zeek workshop in Munich, Germany on 26-27 February 2025. Day 1 features technical presentations by the Zeek team and community. We’ll cover common use cases, recent releases, Zeek’s roadmap, and more. Day 2 offers optional, hands-on training by Zeek team members on Incident Response with Zeek and Writing Zeek Analyzers With Spicy. The schedule is now live:

https://zeek.org/workshop-muc-2025/schedule/

See this site for details:

https://zeek.org/workshop-muc-2025/


Development Updates

There are no updates since the last newsletter.


Zeek in the Community

Seth published a new version of Malcolm. Please see the project site for details:

https://malcolm.fyi/


Zeek in the Enterprise

The recording of the 8 January webinar, Designing Logs in the Real World by Steve Smoot, is live here:

https://youtube.com/live/dHthJNFt-NI

The recording of the 22 January Webinar, Pluggable Cluster Backends, by Arne Welzel, is live here:

https://youtube.com/live/FPU6clovKUI


Friends of Zeek

The Suricata project released version 7.0.8. Visit their site for details:

https://suricata.io/download/


Upcoming Events

The next webinar is Wednesday 5 February at 1 pm ET. Tim Wojtulewicz will discuss the Zeek Telemetry Framework. Register for free here:

https://us06web.zoom.us/webinar/register/WN_Nsq4w6d4Rl2liPmd1_W1fg

The next Training Group Call is 14 February at 12 noon ET. Here is the Zoom link:

<https://ESnet.zoom.us/j/6445948648>

Meeting ID: 644 594 8648

Passcode: Rockon!

The next Zeek Community Call is scheduled for 5 March at 1 pm ET. There is no need to register. Here is the Zoom link:

https://us06web.zoom.us/j/99882457331?pwd=WVZLRGtpbmx1V2FqSnlRT1FLRC9lQT09


Zeek Package Updates

Changes to packages are available via this search:

https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed

The https://packages.zeek.org site reported the last 5 updates as of 2 June:

1/28/25, 4:14 AM shodan-zeek

1/27/25, 9:20 PM ja4

1/24/25, 3:25 PM zeek-spicy-wireguard

1/24/25, 3:23 PM zeek-spicy-ipsec

1/24/25, 3:21 PM zeek-spicy-openvpn


Get Involved

If you have any comments or material for the newsletter please email news@zeek.org or join the #news Slack channel.

https://zeekorg.slack.com

Here is an invitation to the Slack channel:

https://join.slack.com/t/zeekorg/shared_invite/zt-12z1pjy93-zuVGuT1BF~yUJJvERxhp7g

Stay up to date by joining the Zeek Discourse:

https://community.zeek.org

Subscribe to our YouTube channel:

https://youtube.com/c/Zeekurity

Follow us on Mastodon:

https://infosec.exchange/@zeek

The old mailing list archives now redirect to this site:

https://community.zeek.org/archives/list/zeek@lists.zeek.org/

If you’d like to read the Leadership Team meeting notes, they are here:

https://github.com/zeek/zeek/wiki/LT-Meeting-Notes

Follow us on LinkedIn:

https://www.linkedin.com/company/zeekurity

To search LinkedIn for jobs mentioning Zeek skills, use this query:

https://www.linkedin.com/jobs/search/?keywords=zeek

See you next time!