Skip to content
Corelight DefeNDRs

Corelight DefeNDRs

TechnologyTech News23 episodes
Gain clear, actionable intelligence from Corelight's network defense experts. Corelight DefeNDRs translates complex cybersecurity detection challenges into concise, practical episodes designed to support faster, smarter decision-making across modern security teams.
Latest episode

All Episodes

Episode 23 - Inside Zeek 9: Modernizing Open Source Network Monitoring & Agentic Security Scanning

Episode 23 - Inside Zeek 9: Modernizing Open Source Network Monitoring & Agentic Security Scanning

21 min 33 sec
In this episode, host Richard Bejtlich sits down with Christian Kreibich, Zeek's technical lead, to unpack the upcoming Zeek 9 release and what it means for practitioners. Christian explains how the project structures its three-releases-a-year cadence and how the team has spent recent cycles modernizing Zeek—including the shift to ZeroMQ for cluster messaging and new systemd-based cluster orchestration. A major thread is security: alongside longstanding fuzzing and static analysis work, the team is now navigating a wave of agentic, LLM-driven security scanning, with preliminary internal efforts surfacing 50–70 high-severity findings and parallel initiatives from OpenAI/Trail of Bits and Anthropic. The conversation also covers the migration from BinPAC to Spicy for safer protocol parsing, why the team favors Spicy over Rust for writing analyzers (while eyeing Rust elsewhere), the ongoing Microsoft Defender for Endpoint collaboration bringing Zeek to Windows, and a clear roadmap toward cloud-native packet ingestion, better tunnel handling, and a simpler packaging ecosystem. It's a grounded look at how a mature open source project stays modern without breaking what works.
Play episode
Episode 22 - The CTO's Case for AI: Fixing Bugs, Vibe Coding, and the Future of Dev Jobs

Episode 22 - The CTO's Case for AI: Fixing Bugs, Vibe Coding, and the Future of Dev Jobs

15 min 25 sec
In this episode, host Richard Bejtlich sits down with Steve Smoot, Chief Technical Officer at Corelight, to explore how AI is reshaping the daily work of engineers and defenders alike. Steve traces his path from early employee to CTO and explains why the flexibility of Open NDR—where a simple ten-line Zeek or Spicy script can solve a customer's edge case without a full product release—remains a core advantage. The conversation digs into practical realities of working with large language models: using AI to navigate unfamiliar code bases, the persistent danger of hallucinations (including a memorable Suricata example), and the classic programming trap where a routine's label no longer matches what the code actually does. Steve and Richard also tackle the anxiety around entry-level technical jobs, offering a grounded, economics-informed counterpoint to doom forecasts, and make the case that architecture, maintainability, and truly understanding the business problem are the durable human skills in an AI-assisted world. It's a candid look at where development is heading—and why understanding the problem still matters more than writing the code.
Play episode
Episode 21 - Building AI Harnesses to Unify Detection and Response

Episode 21 - Building AI Harnesses to Unify Detection and Response

15 min 49 sec
Corelight Senior Security Engineer Jordan Hair joins Richard Bejtlich to break down how defense teams can leverage agentic AI harnesses to transform traditional security operations. By wrapping deterministic code around large language models, Hare created automated agents for alert triage, threat hunting, and detection engineering that shrink routine investigations from 45 minutes down to seconds. He emphasizes the necessity of maintaining a human-in-the-loop verifier at critical decision points, while demonstrating how this AI-assisted workflow collapses traditional SOC silos—enabling a single engineer to seamlessly manage the entire lifecycle from initial threat hunt to incident response. Learn more about Corelight's use of TAC GPT-5.5: https://www.linkedin.com/posts/openai-for-business_corelight-uses-codex-security-to-move-faster-activity-7477439412524470272-oMWe
Play episode
Episode 20 - NDR Essentials: Why Network Data Still Defines Detection

Episode 20 - NDR Essentials: Why Network Data Still Defines Detection

18 min 48 sec
Richard Bejtlich joins Vince Stoffer to unpack the ideas behind his new book on network detection and response, starting with a practical distinction: NSM is a strategy, while NDR is a product. The conversation explores what teams should expect from network data, how alerts and threat hunting work together, why prevention eventually fails, and how AI can help practitioners investigate unfamiliar logs, alerts, and artifacts without replacing human judgment. Richard also reflects on the writing process, the pressure of creating technical material while doing the work, and why the future of NDR depends on trustworthy data, clear investigation paths, and analysts who know when to question the machine. Download the NDR Essentials book: https://corelight.com/cp/ndr-essentials
Play episode
Episode 19 - The Cap on Inference: Proving How Network Data Quality Drives AI Security ROI

Episode 19 - The Cap on Inference: Proving How Network Data Quality Drives AI Security ROI

19 min 27 sec
In this episode, host Richard Bejtlich sits down with Corelight Co-founder and Chief Strategy Officer Greg Bell to unpack groundbreaking research that quantifies exactly how data quality impacts AI-driven security automation. Moving past qualitative industry hype, Greg shares hard evidence from an empirical experiment pitting leading AI agents against real-world Capture the Flag (CTF) challenges and incident response report writing. The findings reveal a dramatic truth: basic firewall and flow logs place a hard cap on inference, throttling an LLM's capacity for deep insight. By upgrading to higher-fidelity, densely linked network data, teams can boost automated threat hunting accuracy, eliminate costly LLM hallucinations, and dramatically reduce token consumption budgets by enabling security agents to solve problems twice as fast. Read the full research paper: https://corelight.com/blog/data-quality-limits-ai-soc-performance
Play episode
More episodes