Code Monkey home page Code Monkey logo

zeek-agent's Introduction

Zeek Agent

The Zeek Agent is an endpoint monitoring tool for Linux that reports, by default, socket and process events to Zeek. Event data is captured from Audit using the Unix domain socket plugin that comes with Audisp, and is then presented to Zeek as an SQL database (using SQLite virtual tables internally).

Zeek-Agent can optionally also interface to osquery, allowing Zeek to access almost all the endpoint information that it provides (excluding only evented tables).

Pre-built, statically linked zeek-agent packages are available on the releases page.

On the Zeek side, the Zeek Agent Framework provides the API access Zeek Agents, as well as some default scripts recording endpoint activity into Zeek logs.

Documentation

The documentation has been moved to the Zeek Agent Wiki, and contains guides on building, configuring and extending the Zeek Agent project.

For convenience, the build and configuration guides can be accessed from the following links:

History

Zeek Agent supersedes an earlier osquery extension for Zeek that focused on providingn osquery's tables to Zeek. Zeek Agent provides all the same functionality, but can operate independent from osquery as well. We plan to further extend the events/tables that the agent provides natively.

License

Zeek Agent comes with a BSD license, allowing for free use with virtually no restrictions. You can find it in LICENSE.

zeek-agent's People

Contributors

alessandrogario avatar jsiwek avatar rsmmr avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.