Welcome to the Zeek Newsletter
In this Issue:
TL;DR: Zeek 9.1 development is underway! We also merged an initial DHCPv6 analyzer and are looking for feedback. Plus, Zeek training at NSF Cybersecurity Summit is just around the corner and the Berkeley Workshop recordings are available on YouTube.
Community News & Reminders
-
Community Call Recap: This month we covered the start of Zeek 9.1 development. Steve Smoot shared what LLM testing showed about Zeek data and how he uses Spicy to build OT protocol parsers with LLM help. Watch the recording here. The next call is November 4 at 10am PT. Use this Zoom link to join.
-
Zeek Training at the NSF Cybersecurity Summit (Oct. 27): There’s still time to sign up for Zeek training at NSF Cybersecurity Summit!
-
Discourse Clean Up: We want to make sure the solutions in our forum are up to date. If you have a few minutes, we’re looking for volunteers to help review older threads.
-
Berkeley Workshop Recordings: Revisit the presentations from Zeek Workshop Berkeley 2026 on YouTube.
-
New Blogs: Check out Johanna’s “Reducing Zeek JSON Log Size: Field Name Mapping and Log Filtering Hooks” and Christian’s “Introducing Zeek 9”.
-
Topic of the Month: On Monday we wrapped up “The Detections You Rely On”, you can find the recap from the conversation here. This month’s topic is “What Do You Do With Your Zeek Data?” Join the conversation on Slack.
Development Updates
Development on Zeek 9.1, the next feature release, is underway. The team is also spending significant time on security fixes for issues reported through LLM and AI tooling. Patch releases for 8.0 and 9.0 are expected around the end of October.
We’ve merged an initial version of a DHCPv6 analyzer into Zeek’s master branch. This work was started by first time contributor Van (VoDongVan). Thank you, Van! If you’re using our zeek/zeek-dev container image, or the nightly binary packages, Zeek should now produce a new dhcpv6.log file.
We’re looking for feedback and iterating on this new analyzer towards the 10.0 release. If you are interested in contributing, have opinions or suggestions about the extensibility and event design of the analyzer and its scripts, or can provide packet captures from complex and interesting DHCPv6 setups, please reach out on #5947 on GitHub.
As always, follow development progress on GitHub to stay current with the latest changes.
Zeek Techniques
This month’s tip came from Jan, in response to a question in Slack about keeping Zeek from failing to start when a script or package isn’t there.
If you’ve ever uncommented @load packages in your local.zeek on a system with no packages installed, you know Zeek won’t start. The can_load() function checks whether an @load of a given filename, package, or path could succeed by looking for matching scripts in your ZEEKPATH. That means you can guard optional loads instead of letting them break startup:
@if ( can_load("packages") )
@load packages
@endif
Keep in mind that can_load() only checks that the files exist. It doesn’t parse or validate the script itself, so a package with errors in it will still fail when Zeek loads it.
Share your tricks, shortcuts, or techniques with us using this form.
Packages
Anyone in the community can write add-on functionality for Zeek via packages.
- Browse Zeek packages: https://packages.zeek.org
- Head to our zkg package manager documentation to get started on your own
- Questions? Check out #package-sharing to get help
Recently added or updated packages are always visible on GitHub directly, via the following search of pull requests to our package repository:
https://github.com/zeek/packages/pulls?q=is%3Apr+is%3Aclosed
Recent Updates:
Get Involved
- Share ideas or content: news@zeek.org or #security-news on Slack.
- Stay connected: Discourse • YouTube • Mastodon • Bluesky • LinkedIn
- Check out Leadership Team meeting notes for insider updates.
- Looking for Zeek jobs? See openings on LinkedIn.
Thanks for being part of the community. We’ll see you next time!
