Deployment Methods
The Critical Path Security Léargas Platform is available in multiple form factors to meet a variety of enterprise deployments. For data centers and traditional server closets, Léargas is available as a 1U or 2U appliance sized to your performance requirements.
The Critical Path Security Léargas Platform can also be deployed as a VMware Open Virtual Appliance (OVA), or in Amazon Web Services (AWS) and Google Cloud Platform (GCP).
Real-Time, Scalable Protocol Analysis
The Critical Path Security Léargas Platform provides in-depth network traffic analysis by inspecting all network traffic, multi-contextually and multi-dimensionally — capturing every available protocol event, performing file extraction for additional analysis, and delivering application-level insights.
Threat Intelligence and Anomaly Detection
The Critical Path Security Léargas Platform integrates directly with Splunk through our custom Splunk application, or can be used directly through the Léargas User Interface — with cutting-edge Anomaly Detection built in, so you can observe and respond to incidents faster.
About Zeek
Zeek has a long history in the open source and digital security worlds. Vern Paxson began developing the project in the 1990s under the name "Bro," as a way to understand what was happening on his university and national laboratory networks. Vern and the project's leadership renamed Bro to Zeek in late 2018 to mark its expansion and continued development.
Zeek is not an active security device like a firewall or intrusion prevention system. Instead, Zeek sits on a "sensor" that quietly and unobtrusively observes network traffic, creating compact, high-fidelity transaction logs suitable for a SIEM system. Critical Path Security is an active collaborator in the Zeek community, and the Léargas Platform remains true to open source values, with ongoing contributions to the project — including continually updated, Zeek-formatted Threat Intelligence Feeds, free to use.
Zeek-IDS Professional Services
With company founders who are active members of the Zeek community, and a former developer of a commercial Zeek-based platform, Critical Path Security can advise and consult from a unique perspective.
The problem: too many alerts, too little context. Missing an intrusion on your network probably isn't because you don't have enough log data — it's more likely that you're missing the visibility you need into network traffic. Zeek looks at traffic from a contextual point of view and alerts on correlated indicators of compromise, rather than static, atomic indicators.
Our dedicated research team develops wire-level behavioral detections for Zeek, with experience building custom detections in diverse environments including ICS and SCADA.
“Cheers gentlemen, thank you for a flawless execution and delivery.” — T.M.
Zeek IDS Use Cases
Here's how organizations put the Léargas Platform to work solving real-world problems:
- Anomaly Detection: Advanced detection methods coupled with curated threat intelligence reduce your MTTR and surface threats traditional SIEM platforms don't reveal.
- Correlated Vulnerability Management: Vulnerability data correlated directly with network traffic and asset manifests — not optional, a requirement.
- Interconnected Hybrid Network Visibility: One vantage point across on-premises and cloud infrastructure to assess risk and respond quickly.
- Remote & Hybrid Work: Visualize the interconnectedness of your entire environment, no matter where devices and users are located.
- Data Exfiltration: Statistics on notable events exhibiting exfiltration behaviors — effective on encrypted or unencrypted streams.
- Encrypted Traffic Investigation: Insight into events involving encrypted protocols such as SSH, SSL, and SMTP/TLS.
Zeek Intelligence Network
Critical Path Security provides free and subscription-based Zeek-formatted threat intelligence feeds to bring immediate value to your Zeek deployments. Our free threat feeds include Abuse.CH, AlienVault OTX, Binary Defense Systems, Emerging Threats Compromised IPs, OpenPhish, Georgia Tech PREDICT, our own Illuminate Threat Intelligence Network, Rutgers SSH brute-force lists, and TOR exit nodes.

