Identifying and detecting ScoutC2 malware
Learn how Corelight detects ScoutC2 malware using Zeek, SIEM queries, and Suricata rules for distinctive HTTP paths, methods, headers, and payload...
Learn how Corelight detects ScoutC2 malware using Zeek, SIEM queries, and Suricata rules for distinctive HTTP paths, methods, headers, and payload...
Richard Bejtlich introduces NDR Essentials, a guide to using high-fidelity network evidence for detection, response, and threat hunting.
Discover what defending the Black Hat NOC taught me about using Model Context Protocol (MCP) to build an agentic SOC and accelerate threat hunting.
Discover what defending the Black Hat NOC taught me about using Model Context Protocol (MCP) to build an agentic SOC and accelerate threat hunting.
Corelight Performance and Asset Visibility unlocks SecOps and NetOps intelligence from one sensor, with device classification and anomaly-first...
Corelight Sensor v29.1 turns your existing sensors into one platform for SecOps and NetOps, with gap-free forensic evidence behind every alert.
At Black Hat Asia, everyday IoT devices exposed authentication tokens and credentials over cleartext HTTP, showing what the network sees but...
North Korean operatives are infiltrating companies as IT workers. See why traditional security misses them, and how network traffic reveals the truth.
Network visibility is your ground truth in the age of the identity perimeter. See how Corelight integrates with Entra ID and CrowdStrike.