Sign inSign up

cernity/zeek-notice

By cernity

Updated 9 days ago

Promote Zeek notices into findings

Image
0

756

cernity/zeek-notice repository overview

Cernity — zeek-notice

Promote Zeek notices into findings.

Part of Cernity — central network detection & response (NDR) analytics for Suricata sensors. Suricata inspects packets at the edge and ships telemetry; Cernity runs the heavy, stateful, Zeek/RITA-style analysis centrally and emits security findings to your SIEM.

Raw network telemetry is analytics input. Security findings are SIEM input.

This image

cernity/zeek-notice — Promote Zeek notices into findings.

Quickstart

See a finding end to end with no live sensor:

docker compose -f deploy/quickstart/docker-compose.yml up
Deploy
  • Single host — Docker Compose (evaluation / small sites)
  • Manual multi-server — Compose across your own hardware, no orchestration
  • Kubernetes — Helm chart with autoscaled detectors

Scales to ~1,000 sensors / ~10 Gbps of edge inspection. Full docs, architecture, and sizing guide: https://github.com/cernity/cernityndr

License

Source-available under the PolyForm Perimeter License 1.0.1 — use it any way you like, except providing it to others as a competing product. "Cernity" is a trademark of the Cernity Project.

Tag summary

Content type

Image

Digest

sha256:097eefeff

Size

121.4 MB

Last updated

9 days ago

docker pull cernity/zeek-notice