# Zeek

> Use this tool when you need to analyze network security data from PCAP files or perform traffic monitoring and intrusion detection tasks. Zeek-MCP solves problems related to network security analysis by providing a bridge between AI assistants and the Zeek network security monitor, taking PCAP files as input and outputting structured data in formats like pandas DataFrames. It is particularly useful in contexts where automated network security analysis is required, without needing direct interaction with Zeek's command-line interface.

Canonical page: https://skillsregistry.net/skills/gabbo01-zeek  
JSON: https://api.skillsregistry.net/v1/skills/gabbo01-zeek

## Description

Zeek-MCP provides a bridge between AI assistants and the Zeek network security monitor through the Model Context Protocol. It offers tools for executing Zeek analysis on PCAP files and parsing the resulting log files into structured data formats. The implementation handles the complete workflow from running Zeek commands to cleaning up previous log files and converting the tabular output into pandas DataFrames for easier analysis. Built with Python and FastMCP, it supports both stdio and Server-Sent Events (SSE) transport methods, making it particularly valuable for network security analysis, traffic monitoring, and intrusion detection tasks without requiring users to interact directly with Zeek's command-line interface.

## Trust

- **Trust score (0–1):** 0.89
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** monitoring
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/gabbo01-zeek)
- **Repository:** <https://github.com/gabbo01/zeek-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "gabbo01-zeek"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/gabbo01-zeek` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/gabbo01-zeek/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
