Network visibility
Context-enriched, high-fidelity, AI-ready data delivers a single source of truth for complete visibility.
Authoritative, AI-ready network evidence–the foundation for your security operations
Visibility into all network traffic, including East-West, encrypted, and ICS/OT systems, and deep analysis across 70+ data types with enriched and interconnected data to eliminate data fragmentation.
How Corelight transforms network traffic into network evidence
Network evidence is a complete, structured record of everything happening on your network, built from the traffic itself.
1. Data cleanup
The sensor captures a copy of all traffic out-of-band. It then deduplicates and cleans the data, discarding redundant multicast traffic to ensure a clean, efficient dataset for analysis.
2. Context enrichment
The sensor applies live external context before the logs are even generated. This includes threat intelligence (IOCs and YARA rules) and asset identification to associate IP addresses with known devices and users.
3. Analytics
Powered by Zeek®, the sensor performs deep protocol parsing across 70+ data types. It translates raw packets into meaningful events, such as DNS replies or SSL handshakes, and links them all via a UID.
4. Post-processing
Finally, the evidence is optimized. Data aggregation can reduce log volume by up to 80% without losing security context. This authoritative evidence is then routed to Corelight Investigator, a SIEM, or a cost-effective data lake for long-term forensics.
Use cases
Prove the full attack timeline, from first connection to exfiltration
By assigning a Unique Connection ID (UID) to every session at ingestion, Corelight network evidence enables a session-aware approach that automatically links events such as DNS queries, SSL handshakes, and file transfers into a cohesive narrative while maintaining contextual persistence across NAT or proxy boundaries. By normalizing fragmented packet data into authoritative sequences, this telemetry reduces data dimensionality and noise, ensuring high-fidelity attribution and providing a clear causal chain of activity that accelerates triage.
Detect lateral movement via protocol analysis
By analyzing enriched metadata from RDP and SMB protocols, such as unusual session patterns or spikes in file renaming and deletion, security teams can identify the critical staging phase of an attack.
Accelerate contextual visibility with threat intelligence enrichment
By automatically correlating incoming network evidence with high-fidelity threat intelligence at the point of ingestion, security teams gain immediate insight into known malicious infrastructure. This enrichment provides context such as threat scores, adversary attribution, and malware families from curated feeds of indicators of compromise. This proactive visibility transforms raw metadata into an actionable map of organizational risk, ensuring that connections to suspicious IPs, file hashes, or domains are instantly highlighted within the broader network narrative.
Map the cryptographic landscape for PQC readiness
Corelight sensors identify and log cryptographic protocols and cipher suites observed in network traffic. Corelight’s Open NDR network evidence provides detailed telemetry on cryptographic protocols and algorithms in use by parsing SSL/TLS handshakes and SSH banners, identifying cipher suites, key lengths, and certificate details for risk assessment and transition planning.
Immutable network audit logging for regulatory compliance
Corelight network evidence is an authoritative record of digital transactions, decoupled from monitored assets and resistant to local log tampering. By capturing "off-the-wire" metadata, it offers the critical "negative evidence" necessary to prove that a sensitive database was not accessed during a breach, thereby limiting regulatory liability for mandates like GDPR and HIPAA. Ultimately, high-fidelity telemetry provides a centralized, standardized foundation for reporting, enabling organizations to demonstrate consistent security controls across fragmented hybrid environments to auditors and legal bodies.
Passive asset discovery, classification and service inventory
Corelight network evidence provides zero-impact discovery by extracting identifying data from natural network communications rather than using intrusive active scans. Through the analysis of DHCP, HTTP User-Agents, and protocol-specific banners, telemetry enables precise device fingerprinting, asset classification, and service enumeration, creating a searchable inventory of hardware and potentially vulnerable applications. This methodology enables discovery of vulnerable assets, exposed services, and cryptographic mechanisms.
Gartner® and Peer Insights™ are trademarks of Gartner, Inc. and/or its affiliates. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose
Corelight has been a reliable and strategic partner in enhancing our network visibility and security posture.
IT Associate, Travel and Hospitality
Gartner® and Peer Insights™ are trademarks of Gartner, Inc. and/or its affiliates. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose
Corelight sensors provide excellent visibility for the protection of our organization's cyber security program.
IT Security & Risk Management Associate, Government
Open NDR Platform difference
Only Corelight enriches and interconnects each transaction using a Unique ID (UID), producing a detailed, machine-readable narrative essential for full historical reconstruction and eliminating blind spots.
| ExtraHop | Darktrace | Vectra AI | Corelight |
| Enriched metadata optimized for speed, but outputs are proprietary. Analysts have to rely on summaries they can't independently validate. | Black-box scores and anomaly outputs. No way for analysts to validate, reproduce, or escalate findings from raw evidence. | Behavioral context accompanies detections, but original network transactions aren't accessible and can’t be exported. | Zeek-powered evidence, with every event linked by a unique identifier (UID), for a single, corroborated narrative. Analysts can pivot from alert to full proof and port evidence into any tool, not just a score. |
| ExtraHop | Darktrace | Vectra AI | Corelight |
| Historical replay limited to retained summaries in proprietary EXA recordstore appliances. Portability outside ExtraHop requires additional integration work. | Alert timelines only, with no replayable record of underlying network activity for post-breach reconstruction. | Behavioral history retained; reconstructing full attack timeline requires additional data integration. | An immutable record of all network activity, with compact metadata for long lookback at scale, Smart PCAP for targeted full-packet retention. Audit-ready for NIS2, DORA, and SEC disclosure. |
| ExtraHop | Darktrace | Vectra AI | Corelight |
| Proprietary data formats block custom AI/ML pipelines and lock teams into ExtraHop's automation abstractions. | Self-learning models are closed. Data cannot be exported or used to train external models outside the Darktrace ecosystem. | Built-in AI/ ML models, none open or tunable. Portability limited to the Vectra ecosystem. | Structured, machine-readable evidence in open JSON/TSV feeds any AI SOC pipeline or LLM out of the box. You own the data, with extensibility for custom logic and no vendor lock-in. |
Unlocking deep visibility
Network security monitoring with Zeek
Unify network visibility with Zeek®, the world's most widely used network security monitoring engine with over 10,000 deployments worldwide. Corelight transforms raw traffic into high-fidelity, protocol-rich metadata across on-premises, hybrid, and cloud environments.
IDS with Suricata
Identify known threats with speed and precision across the entire network. Corelight’s curated signature integrates high-performance Suricata IDS to deliver a robust first line of defense against known malware, C2 infrastructure, and exploitation attempts.
File analysis with YARA
Detect and classify known and emerging malware with pattern-matching directly from network traffic. Corelight’s static file analysis integrates the YARA framework to provide a scalable, automated engine that unmasks file-based obfuscated threats, ransomware, and APTs that bypass traditional endpoint and perimeter tools.
Smart PCAP
Bridge the gap between high-level metadata and raw packets with Corelight Smart PCAP, a purpose-built forensic solution for security teams. By capturing only the packets that matter Smart PCAP extends forensic retention by up to 10x while embedding 1-click retrieval links directly into your existing SIEM investigative workflows.
Case study
Carrefour, a top ten global retailer, uses Corelight to expand visibility & detect attacks at the earliest stages
Case study
National CERT disrupts coordinated zero-day attack on European critical infrastructure
Case study
Global financial firm mitigates multi-platform identity attack in under two hours
Maximize ROI with services and training from Corelight
Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.
-
Accelerate implementation and time to value with health checks
-
Precision engineering for detection calibration, and customization
-
Expert-led training and education services
FAQ
What is the benefit of Corelight building on Zeek?
Zeek is the gold standard for network security monitoring due to ongoing community contribution, performance at scale, and provably better high-fidelity data. Corelight leverages this open-source foundation to ensure its evidence is always transparent, community-vetted, and future-proof.
How does Corelight network evidence reduce my SIEM or storage costs?
Corelight reduces log volume by up to 80% through aggregation, normalization, and intelligent filtering, focusing on compact, high-value Zeek metadata, allowing you to retain years of historical evidence cost-effectively.
Can Corelight see threats in encrypted or East-West traffic?
Yes. Corelight provides critical visibility into East-West and encrypted traffic, areas often missed by perimeter tools. It analyzes TLS handshakes and protocol activity to expose threats and anomalies without requiring full decryption.
How does the Unique ID (UID) feature speed up investigations?
The UID automatically links all related logs (DNS, HTTP, file transfers) from a single connection into one narrative. This eliminates the need for analysts to manually stitch data together, enabling them to move from a high-level alert to a complete attack timeline instantly.
Is Corelight compatible with my AI/ML security initiatives?
Absolutely. Corelight’s data is structured, open (JSON/TSV), and machine-readable, making it "AI-ready" out-of-the-box. You can feed this evidence directly into LLMs and ML models to train advanced detection capabilities without costly data engineering.