What you are evaluating
Zeek alone is not a staffed service or a complete commercial NDR console. Operators supply deployment, storage, search, detection content, access controls and case handling. Corelight’s commercial products are separate from the open-source project.
A useful evaluation context
Learners and engineering teams building a concrete understanding of network evidence before evaluating managed platforms.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Offline packet captures can be analyzed into connection and protocol logs.
- Shared record identifiers support pivots across related log types.
- The scripting language allows operators to extend local analysis and detection behavior.
Where it fits in the work
- Use the official quick-start sample capture in an isolated working directory.
- Correlate a connection with its HTTP and unusual-protocol records.
- Explain the observation and preserve the capture and analysis version so someone else can reproduce it.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
Follow the official offline quick-start exercise and join related records by their UID. Identify what makes the unusual HTTP method noteworthy without assuming it was an intrusion.
Evidence to look for
Save the analysis command, Zeek version, capture hash and correlated record identifiers. Explain the difference between telemetry, a detection and a confirmed incident.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Who operates the capture, storage and search pipeline?
- Which scripts and packages are trusted and maintained?
- How are packet data and logs protected and retained?
Names you may encounter: Bro. Historical names do not establish current availability or feature equivalence.