Featured Corelight and Microsoft: A smarter way to fight alert fatigue Streamline alert triage and reduce alert fatigue with Corelight's Microsoft Defender integration, enabling faster, smarter decisions across your SOC. Allen Marin Mar 30, 2026
network security Detecting Quasar Windows RAT Detect Quasar RAT malware with Corelight’s open-source Zeek script, leveraging Quasar’s default TLS configuration. Tillson Galloway Nov 22, 2024
network security Detecting Abuse of NetSupport Manager Learn how to use Zeek to easily detect malicious use of NetSupport Manager. Tillson Galloway Sep 11, 2024
Zeek Detecting CVE-2022-30216: Windows Server Service Tampering Corelight Labs reviewed a POC exploit for CVE-2022-30216 and wrote a Zeek-based detection and released the package on GitHub. Tillson Galloway Aug 9, 2022