Log inSign up
Corelight
3,504 posts
Corelight profile banner
@corelight_inc

Corelight

@corelight_inc
Corelight transforms network data into definitive evidence, powering AI-driven detection and expert-authored workflows, and enabling the AI SOC ecosystem.
San Francisco and Columbus
corelight.com
Joined October 2016
606
Following
4,221
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @corelight_inc
    Corelight
    @corelight_inc
    Aug 31
    Effective agentic triage requires moving beyond black-box AI to deliver complete inspectability at every step of an investigation. In Episode 16 of Corelight DefeNDRs, Richard Bejtlich and Dave Getman discuss how Corelight Investigator synthesizes millions of network log lines
    Image
    00:00
  • @corelight_inc
    Corelight
    @corelight_inc
    1h
    Exploit windows are collapsing, putting more pressure on SOC teams to determine what is actively being exploited right now. AI-powered defense starts with model-ready network evidence, multi-layered threat detection, and agentic workflows that help analysts distinguish immediate
    A person working on a computer with a Corelight interface displayed on the screen. The text reads: "Building an AI-powered defense. 4 structural capabilities to defend against machine-speed threats." A button below says, "Explore the framework." The Corelight logo is at the bottom.
  • @corelight_inc
    Corelight
    @corelight_inc
    23h
    Mythos-class models automate software exploitation at machine speed, and the time-to-exploit window has collapsed from months to hours. Defending against Mythos-class models requires unedited network evidence to power machine-speed detection, triage, and root-cause analysis.
    The image is a graphic for "The CISO's guide to building a Mythos-ready security program" by Corelight. It features a dark background with text about practical guidance for adapting security programs to AI-driven attacks. A button labeled "Download the guide" and a preview of a document are included.
  • @corelight_inc
    Corelight
    @corelight_inc
    Sep 3
    Modern SOC workflows rely on structured network telemetry to sharpen visibility and speed up investigations. Visit @corelight_inc at Booth S3 from Sept. 14 to 16 at Splunk .conf2026 to see how high-fidelity network evidence powers modern investigation workflows. Co-Founder Greg
    Image
    GIF
  • @corelight_inc
    Corelight
    @corelight_inc
    Sep 2
    Data moves across networks every day. Defenders still have to determine when that movement deserves investigation. Transfer volume, destinations, timing, and protocol behavior help defenders recognize suspicious data movement before relying on indicators alone. Explore how
    Graphic with a software interface with green binary code background and text saying, "Data movement doesn't always mean data theft. Context determines what deserves investigation." The Corelight logo is at the top left of the graphic.
    The image features the Corelight logo and the text: "Why investigators ask questions. Data moves every day. The investigation begins when the behavior no longer aligns with what is expected." The background is a digital-style design with binary code.
    The image displays a Corelight graphic. It features a list titled "What defenders monitor," including unusual data transfer volume, first-time destinations, cloud storage usage, protocol behavior, and transfer timing. A pink warning icon with an exclamation mark is at the bottom right. The background is dark with binary code.
    A  graphic from Corelight featuring the text: "Investigate suspicious data movement." It invites readers to "Learn how network evidence helps uncover potential data exfiltration" with a button labeled "Read the blog." The background displays a blurred screen with lines of computer code.
Advertisement
Advertisement