Alternatives to Zeek
Network analysis framework that turns traffic into high-level activity logs. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
Zeek
Network analysis framework that turns traffic into high-level activity logs.
Replacements
Listings that take over the same core job as Zeek.
Suricata
Inspect network traffic with an intrusion-detection engine.
Suricata replaces Zeek's semantic activity logs with a rule-based intrusion-detection engine that supports inline prevention, runs on Linux only, and needs suitable traffic access and maintained rules.
Snort
Open-source intrusion detection and prevention system.
Snort moves from activity logging to rule-based intrusion detection and inline prevention, adds Windows support, and needs rule tuning, with the newest subscriber rule set being paid.
Similar software
Related functionality, not a direct replacement.
Wazuh Agent
Endpoint agent that feeds a Wazuh server with security and compliance data.
CrowdSec
Detect suspicious behavior in server logs and web traffic.
Falco
Detect unusual runtime behavior on Linux systems.
Kismet
Wireless detector, sniffer and intrusion detection system for Wi-Fi, Bluetooth and RF.
Velociraptor
Endpoint monitoring and digital forensics platform driven by a query language.
bettercap
Network reconnaissance and man-in-the-middle testing framework.