Corelight Bright Ideas Blog: NDR & Threat Hunting Blog

Locked Shields 2026: Network Evidence in Action | Corelight

Written by Ed Smith | Jul 23, 2026 2:30:00 PM

Locked Shields 2026 brought together more than 4,000 participants from 41 nations for a live-fire cyber defense exercise built around the kind of pressure SecOps teams know well: Critical systems under attack, incomplete context, multiple tools, and no time to waste.

For Corelight, the exercise reinforced a practical lesson: In high-pressure defense, network evidence is not just another data source. It is the connective tissue that helps analysts understand what happened, where it happened, and what to do next.

During the exercise, Corelight supported defenders with passive monitoring, enriched Zeek® logs, custom detection content, Investigator-driven threat hunting, and integrations with tools already in use across the defensive environment. The result was a clearer path from raw network activity to operational action.

Multiple Blue Teams used Corelight as part of their defense strategy, including teams that ranked among the highest-scoring participants in the exercise. Their performance underscored a core lesson from Locked Shields: When defenders have rich network evidence, they can move faster from anomaly to investigation, and from investigation to response.

Here is how Corelight helped defenders turn tactical chaos into structured, proactive defense.

Defending the fictional state of Berylia

The Locked Shields scenario centers on Berylia, a fictional island nation under aggressive cyberattack from an adversary known as Crimsonia. Crimsonia represents a highly sophisticated nation-state threat actor attempting to disrupt Berylia's critical infrastructure, including military systems, water purification plants, electric power grids, and the central bank.

Blue Teams were tasked with maintaining Berylia’s networks and services while defending against large-scale attacks across critical infrastructure, cloud environments, and scenarios shaped by AI-driven threats.

Where network evidence made the difference

Passive monitoring for critical infrastructure (ICS/SCADA): Critical infrastructure environments are difficult to defend because many operational technology systems cannot support endpoint agents without introducing risk. In those environments, passive network monitoring gives defenders visibility without touching the systems they are trying to protect.

For Locked Shields 2026, Corelight Labs developed custom detection content for SCADA network activity, including Modbus-specific detections created for the exercise environment. That gave defenders a way to identify suspicious behavior in industrial network segments while preserving the stability of sensitive systems.

Extensive log enrichment: Context is everything when responding to a fast-moving threat. Our team worked ahead of the exercise to expand Zeek enrichment packages used in previous years. With modifications by our Labs team, Corelight Sensors were able to dynamically enrich logs with operational context, including:

  • VLAN and inner-VLAN tags.
  • Calculated SSL certificate ages.
  • Extended local originator and responder fields.
  • Specific hostnames, operating systems, team designations, capability groups, and network segment data.

By putting asset, segment, and traffic context directly into the logs, defenders could understand the source, destination, and likely ownership of activity without pivoting through separate systems during a time-sensitive investigation.

Rapid threat hunting with Investigator: We also provided teams with our Investigator platform. The speed and efficiency of Investigator stood out to many participants. During the exercise, an analyst reviewing threat-hunting dashboards quickly spotted anomalous metadata and identified active DNS exfiltration within the SCADA network segments. Because Corelight data provided the exact port and service data, the team was able to rapidly track down the responsible segment owner and shut down the malicious service.

Seamless tool integration: Defense in depth requires tools that work well together. Corelight's Open NDR architecture is designed specifically to integrate smoothly with other technology stacks. During the exercise, it seamlessly streamed rich network evidence to AC-Hunter, Elastic, Splunk, and Trend Micro simultaneously.

The fog of war: Navigating real-world friction

The value of Locked Shields is that it lets defenders “train as they fight,” closely mirroring the chaotic reality of live incident response. Defending a network is rarely a clean, sterile process.

For instance, at the start of the exercise, our team experienced a sensor communication failure. After hours of troubleshooting, they discovered that an EDR agent had accidentally been pushed to the host running our platform, completely blocking communications. It was a useful reminder of an old cybersecurity rule: Trust, but verify. Furthermore, teams had to quickly map networks without knowing where SPAN ports were located and deal with the lack of system administrators amid an abundance of security practitioners.

Building global cyber resilience

As threat actors evolve their tactics to bypass traditional perimeters, exercises like Locked Shields are vital for training security teams to stay one step ahead.

Corelight’s continued involvement in this massive NATO CCDCOE exercise underscores our commitment to advancing network detection and response capabilities and partnering with the global cybersecurity community to protect critical infrastructure worldwide.

For more from the Corelight engineers who supported the exercise, listen to Episode 18 of the Corelight Defenders Podcast: “Live Fire Defense at Locked Shields.