Zeek is now a component of Microsoft Windows
corelight.com
corelight.com
I hope they got better over the years, if they want to integrate into such major products...
A zero-ruleset (if you're not looking at actual pattern-matching or IDS functionality) deployment of Suri is surprisingly lightweight and performant, and it's also easy to roll rules for your custom decoders as well if you want to actually alert on certain things instead of just doing straight decoding and dumping to JSON
if ms is getting this data, how the hell can they afford the disk space?! my bro implementation was 250GB/h of disk space for 20k endpoints. I can only fathom what all windows agents would generate.
soo many questions around this still
You do a "pre-summarization" of the data on the client side, and just send a report to the mothership. Consequence of this is that it will result in using CPU resources of the client - and that explains why the telemetry service eats so much of it on Windows.
https://techcommunity.microsoft.com/t5/microsoft-defender-fo...
https://customers.microsoft.com/en-us/story/1540745195786192...
Interestingly you can get access also as small business. Just purchase the Microsoft 365 E5 license. Price is something like 50-70€/month, 12M subscription. This can be convenient, if you have requirements to use this kind of tools from your customers.
And they actually log a lot of stuff. When enabled you can see (on cloud) pretty detailed information on what has happened to workstation.
Zeek script: https://github.com/fox-it/bro-scripts
Presentation: https://old.zeek.org/brocon2015/slides/hu_qi_detection.pdf
People that encountered network security probably know the name "Bro" much better. Apparently they rebranded in 2018.
Wikipedia has the following to say about it:
> Dr. Paxson originally named the software "Bro" as a warning regarding George Orwell's Big Brother from the novel Nineteen Eighty-Four. In 2018 the project leadership team decided to rename the software. At LBNL in the 1990s, the developers ran their sensors as a pseudo-user named “zeek”, thereby inspiring the name change in 2018.
Zeek is cool but I always thought Bro was a neat name for a sec product.
I wonder how long until Palantir rebrands...
even most of the enterprise solutions sold for network monitoring proudly boast that they use bro under the hood for their stream parsing engine.
I agree, and I'd like to understand the reason why "probably" disappeared from the press release. If you claim something, you should be able to back it up with some numbers, right? I'm a big fan of Bro and fully agree with the "leading solution" or "everybody is using it" phrases, I just miss the data that would make it the number one.
I hear this phrase about many software platforms. That's why I'd like to see some numbers before someone uses an absolute qualifier. I have no idea how popular is Zeek against OSSEC, Suricata or Snort these days, I'm just wary of claiming something without providing any justification.
Also startups make up almost nothing of the ecosystem. Fortune 1000 and Gov have millions of different departments that have their own requirements.
Could your POV be somewhat US-centric?
Also the least popular.
I have heard of: Ganglia, nagios, graylog, grafana, science logic and others. And I've used most of them.
As part of Windows, I would speculate it serves a function similar to something like Little Snitch on macOS, but that’s just a guess. Maybe they have something different in mind.
I think it ships with IDS rules nowadays, but we see it generally more for manual impl. We see often fed into Splunk or ELK to feed custom detections, and especially enriching context to simplify investigating alerts by detection tools. Its investment into cross-record correlation IDs make graph-based investigations super effective: you can grab all sessions at an impact period and see them fan out across entities, resources, time, etc!
We mostly see it in sec teams in gov + DIY/code-heavy enterprise. Super popular bc those teams have more time to figure out tuned use of the rich low-level data, maybe budget to store it, and OSS means they can avoid the vendor dance.
CoreLight, who we did a popular webinar with awhile back showing how to enable rich visual hunting & investigation for the data by combining with Graphistry, is the biggest dedicated vendor building hw/sw to make it all more manageable at scale. So seeing in Windows is probably big news for their community..
We're gonna be launching managed support for Zeek soon, where you can just dump Zeek logs in S3 and get out normalized Apache Iceberg tables for all ~43 Zeek logs.
How not to write an opener of your press release.
From "the leader", to (r), to "world's most popular" - so much marketing b/s in so few words. It's just awful.
[1] http://swain.webframe.org/zeek.html
[2] https://en.wikipedia.org/wiki/Locomotion_%28TV_channel%29
use the original name, it's much better:
Microsoft Bro
Here's some of the DNS fields it extracts as it observes the traffic:
https://docs.zeek.org/en/current/scripts/base/protocols/dns/...
Not sure why everyone on HN is freaking out about it. It's actually pretty annoying to have to install Wireshark (including their capture driver) every time I need to debug over-the-wire network data.
[1] https://docs.zeek.org/en/current/scripts/policy/protocols/ss...
[2] https://docs.zeek.org/en/current/scripts/base/bif/plugins/Ze...
Edit: I suppose it could be configured to do that. I've used Zeek in several organizations over the last 15 years and I have never seen it used in that way. However, Zeek running on a client computer (not on a cluster being fed from a 100 Gbit tap or SPAN) would be more scalable. And this announcement is about that.
Here's a nice paper on how Zeek has been configured to monitor fast networks: https://commons.lbl.gov/download/attachments/120063098/100GI...
> I have no idea what the software does but it sounds like network-sniffing, privacy-intruding malware being severely sugarcoated?
It used to be named “Bro” as in “Big Brother”. So yea, it was designed to be very intrusive to privacy concerns.
It reads like a press release, because it is. Note the "Press Release" banner at top, and the "About *" blurbs at the bottom.
> Am I the only one who gets dystopian vibes from this?
No, also the tool's founder, which is why he named it Bro, as in Big Brother.
AKA 80% of Windows development since 2009?
...only that now it's more of a panic attack.