The missing layer in modern detection architecture
Signatures catch known threats and anomaly detection flags deviations. TTP-based detection closes the gap by detecting behaviors mapped to MITRE...
Signatures catch known threats and anomaly detection flags deviations. TTP-based detection closes the gap by detecting behaviors mapped to MITRE...
See how Corelight's network evidence helped Blue Teams cut through the chaos of Locked Shields 2026, from SCADA detections to live DNS exfiltration...
Shadow AI is the blind spot you didn't budget for. Corelight surfaces 80+ AI services in your Zeek logs so you can inventory, prioritize, and enforce...
Discover what defending the Black Hat NOC taught me about using Model Context Protocol (MCP) to build an agentic SOC and accelerate threat hunting.
Discover what defending the Black Hat NOC taught me about using Model Context Protocol (MCP) to build an agentic SOC and accelerate threat hunting.
See how a Black Hat Asia 2026 threat hunt traced rare cleartext HTTP/2 traffic to exposed cookies after repeated QUIC and TLS failures.
At Black Hat Asia 2026, online games exposed cleartext inside TLS streams. See how Corelight uses network visibility to verify encryption.
See how a Black Hat music trivia game exposed unencrypted traffic, weak validation, and the value of network visibility.
After ten Black Hat NOCs, see what network traffic reveals: cleartext passwords, a leaked API key, and infected devices nobody noticed.