At December's Community Call, Benjamin demoed zeek-websocket-rs, the new Rust-based WebSocket bindings for Zeek with support for Python, C++, and Node.js.

Watch the demo: https://www.youtube.com/watch?v=pP2b9lQAZl8&t=426s #Zeek #NetworkSecurity

#OpenSource #Rust #InfoSec

Zeek 8.1, ZeroMQ Integration, WebSocket Bindings & Community News – December 2025 Community Call

YouTube
Made a transparent network bridge on #NixOS which sits between router & #LAN switch, monitoring traffic for #IDS #intrusiondetection , #Suricata and #Zeek capture and analyze packets → #Filebeat ships #logs#Elasticsearch with #GeoIP ingest pipeline → #Grafana setup of dashboard to visualise data is defined in flake itself so using the flake will give the same dashboard. #flake details here https://codeberg.org/adingbatponder/reticulum_nixos_flake/src/branch/main/features/network-appliance
Hardware: HP EliteDesk 800 G1 SFF 16Gb RAM & https://www.jacob.de/produkte/Intel-Ethernet-Server-Adapter-I350-T4-I350T4V2-artnr-2094756.html #i350t4

Malcolm v25.12.1 contains a few critical bug fixes and component version updates.

https://github.com/idaholab/Malcolm/compare/v25.12.0...v25.12.1

  • ✨ Features and enhancements
    • Installer splash screen shows "HEDGEHOG" when using Hedgehog run profile
  • ✅ Component version updates
  • 🐛 Bug fixes
    • Changed field used in Threat Intelligence dashboard's file type table from zeek.intel.file_mime_type to file.mime_type so filters created from it can work on other dashboards
    • link for threat intelligence URL doesn't work correctly from dashboards (behind reverse proxy) (#832)
    • self-signed certificates not accepted by Chrome (#833)
    • Malcolm ISO installer's automatic partitioning may create too-small /var partition (#835)
  • 🧹 Code and project maintenance

Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

#Malcolm #HedgehogLinux #Zeek #Arkime #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

This month's tip: how to process compressed pcaps directly with Zeek.

See the command in the newsletter: https://community.zeek.org/t/zeek-newsletter-issue-57-november-2025/7912

#Zeek #NetworkSecurity #pcap

Corelight@Home: Who’s Your Fridge Talking to at Night? | Corelight

Corelight is excited to announce the Corelight@Home program, bringing Corelight’s enterprise-class Network Detection and Response to home networks.

Our new blog post walks through best practices for writing clean, maintainable scripts.

Read here: https://zeek.org/2025/12/developing-zeek-scripts-with-style/

#Zeek #NetworkSecurity #OpenSource #InfoSec

Some cool stuff happening in Zeek development this month: Zeek 8.1 is almost here, updates on WebSocket bindings, and more.

Get the full rundown in our newsletter: https://community.zeek.org/t/zeek-newsletter-issue-57-november-2025/7912

#Zeek #NetworkSecurity #OpenSource

Zeek Newsletter - Issue 57 - November 2025

Welcome to the Zeek Newsletter In this Issue: Reminders Tip of the Month Community Call Recap Development Updates Packages Get Involved TL;DR: Zeek 8.1 enters final stretch with mid-December fork and ZeroMQ as the new default cluster backend, WebSocket bindings demoed for multiple languages, and CERN workshop spots still available! Don’t Miss This – Reminders for the Community Zeek Workshop (Geneva, Mar. 25-26): Join us for a free, two-day workshop at CERN. Registration and Call for Pre...

Zeek

Our call for presentations is open for the upcoming Zeek workshop at CERN, Using Zeek in your security work? Built custom scripts or plugins? Analyzing protocols with Spicy? We want to hear about it.

https://zeek.org/workshop-cern-2026/call-for-presentations/

#Zeek #NetworkSecurity #ThreatHunting #InfoSec #OpenSource

Malcolm v25.11.0 brings a rebuilt install script and fresh visualizations. Security Onion 2.4.190 updates its Zeek components. Find the full details in the latest Zeek newsletter:
https://community.zeek.org/t/zeek-newsletter-issue-56-october-2025/

#Zeek #Malcolm #SecurityOnion #NetworkSecurity

Zeek Newsletter - Issue 56 - October 2025

Welcome to the Zeek Newsletter In this Issue: Reminders Tip of the Month Community Call Recap Contributor Shoutout Development Updates Ecosystem News Packages Get Involved TL;DR: Zeek 8.0.4 is out with stability improvements, 8.1 development continues with ZeroMQ integration and WebSocket support, and CERN workshop registration is filling fast! Don’t Miss This – Reminders for the Community Zeek Workshop Europe (Geneva, Mar. 25-26) Registration is now open for a free, two-day workshop at ...

Zeek