Overview
Zeek is an open-source network security monitoring (NSM) platform designed to provide comprehensive visibility into network activity. It passively analyzes network traffic and generates detailed logs about connections, protocols, files, and security-related events, helping organizations monitor, investigate, and respond to potential threats.
Unlike traditional intrusion detection systems, Zeek acts as a powerful network analysis framework that allows security teams to inspect application-layer protocols, detect suspicious behavior, and create custom detection policies using its flexible scripting language. It supports a wide range of protocols, including HTTP, DNS, SSL/TLS, SMTP, SSH, FTP, and more.
Zeek is widely used by enterprises, research institutions, government agencies, and security operations centers (SOCs) for threat hunting, incident response, compliance monitoring, and forensic investigations. Its scalable architecture enables deployment in environments ranging from small networks to large, high-speed enterprise infrastructures.
With extensive logging capabilities, integration support for SIEM platforms, and a rich ecosystem of community-developed packages, Zeek provides security professionals with actionable insights into network behavior and helps strengthen an organization's overall cybersecurity posture.
Highlights
- Provides deep visibility into network traffic with detailed protocol analysis, event detection, and comprehensive logging capabilities.
- Supports custom scripting, threat hunting, forensic investigations, and integration with SIEM and security analytics tools for organizations of any size.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/hour |
|---|---|
m4.large Recommended | $0.03 |
t3.micro | $0.03 |
t2.micro | $0.01 |
t3.nano | $0.03 |
t2.2xlarge | $0.03 |
t2.medium | $0.03 |
t3.medium | $0.03 |
t2.large | $0.03 |
t3.large | $0.03 |
r4.large | $0.03 |
Vendor refund policy
No Refund
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Packaged with latest updates as of June/2026
Additional details
Usage instructions
Usage Instruction Connect your instance via SSH, the username is ubuntu. More info on SSH: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AccessingInstancesLinux.html - Run the following commands: #zeek --version
Support
Vendor support
Feel free to reach out anytime. Our support team is available 24x7 for assistance. Email: anant.shahi@pcloudhostings.com Website:
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
