Problem Statement
How does Zeek differ from signature-only NIDS tools?
Explanation
Zeek, formerly Bro, is a passive network security monitor that generates detailed logs and enables custom analysis beyond simple signatures, supporting investigations and hunting.
Code Solution
SolutionRead Only
Outputs: conn.log, http.log, dns.log for timeline and pivoting
