<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Bright Ideas Blog</title>
    <link>https://corelight.com/blog</link>
    <description>Welcome to the Corelight Bright Ideas Blog. We help organizations gain world-class visibility into their network traffic to help detect and prevent attacks.</description>
    <language>en</language>
    <pubDate>Thu, 11 Jun 2026 18:24:46 GMT</pubDate>
    <dc:date>2026-06-11T18:24:46Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Black Hat Asia 2026: From Cat Feeders to Solar Farms | Corelight</title>
      <link>https://corelight.com/blog/black-hat-asia-2026-cleartext-iot-risks</link>
      <description>&lt;p&gt;There is a saying you will hear from veterans in the Black Hat Network Operations Center (NOC): “Threat hunting on the Black Hat network is like trying to find a needle in a stack of needles." With dozens of training classes running live exploit chains, capture-the-flag traffic, and researchers probing every corner of the internet, our Corelight sensors generate a rich set of Zeek logs, many of which can look suspicious in varying degrees.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a saying you will hear from veterans in the Black Hat Network Operations Center (NOC): “Threat hunting on the Black Hat network is like trying to find a needle in a stack of needles." With dozens of training classes running live exploit chains, capture-the-flag traffic, and researchers probing every corner of the internet, our Corelight sensors generate a rich set of Zeek logs, many of which can look suspicious in varying degrees.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=8645105&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fcorelight.com%2Fblog%2Fblack-hat-asia-2026-cleartext-iot-risks&amp;amp;bu=https%253A%252F%252Fcorelight.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>network detection response</category>
      <category>SOC</category>
      <category>BlackHat</category>
      <category>featured</category>
      <pubDate>Wed, 10 Jun 2026 16:49:40 GMT</pubDate>
      <guid>https://corelight.com/blog/black-hat-asia-2026-cleartext-iot-risks</guid>
      <dc:date>2026-06-10T16:49:40Z</dc:date>
      <dc:creator>Ben Reardon</dc:creator>
    </item>
    <item>
      <title>The North Korean IT worker threat: A modern insider risk | Corelight</title>
      <link>https://corelight.com/blog/north-korean-it-worker-insider-threat</link>
      <description>&lt;p&gt;The threat is coming from inside the organization. It is coming from a laptop farm three states over, routed through a proxy, and operated by a threat actor sitting on the other side of the globe.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The threat is coming from inside the organization. It is coming from a laptop farm three states over, routed through a proxy, and operated by a threat actor sitting on the other side of the globe.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=8645105&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fcorelight.com%2Fblog%2Fnorth-korean-it-worker-insider-threat&amp;amp;bu=https%253A%252F%252Fcorelight.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>network detection response</category>
      <category>SOC</category>
      <category>insider threat</category>
      <category>CISA</category>
      <category>featured</category>
      <category>AI</category>
      <pubDate>Mon, 08 Jun 2026 21:33:47 GMT</pubDate>
      <guid>https://corelight.com/blog/north-korean-it-worker-insider-threat</guid>
      <dc:date>2026-06-08T21:33:47Z</dc:date>
      <dc:creator>Tim Chiu</dc:creator>
    </item>
    <item>
      <title>Identify in the SOC: Why Network Visibility Still Matters | Corelight</title>
      <link>https://corelight.com/blog/identity-soc-network-visibility</link>
      <description>&lt;p&gt;Long gone are the days where usernames &lt;a href="https://www.beyondidentity.com/resource/the-history-and-future-of-passwords"&gt;were all you needed&lt;/a&gt; to secure a network. The same is true for your Security Operations Center (SOC) analysts trying to investigate a threat. "Who is jdoe05 and why are they logging into this server?" is a critical question to answer during an investigation, one that neither NDR (Network Detection and Response) nor EDR (Endpoint Detection and Response) can answer directly. Enter the Identity Provider (IdP).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Long gone are the days where usernames &lt;a href="https://www.beyondidentity.com/resource/the-history-and-future-of-passwords"&gt;were all you needed&lt;/a&gt; to secure a network. The same is true for your Security Operations Center (SOC) analysts trying to investigate a threat. "Who is jdoe05 and why are they logging into this server?" is a critical question to answer during an investigation, one that neither NDR (Network Detection and Response) nor EDR (Endpoint Detection and Response) can answer directly. Enter the Identity Provider (IdP).&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=8645105&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fcorelight.com%2Fblog%2Fidentity-soc-network-visibility&amp;amp;bu=https%253A%252F%252Fcorelight.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>network detection response</category>
      <category>SOC</category>
      <category>Crowdstrike</category>
      <category>featured</category>
      <category>Entra ID</category>
      <category>identity provider</category>
      <pubDate>Thu, 04 Jun 2026 16:46:36 GMT</pubDate>
      <guid>https://corelight.com/blog/identity-soc-network-visibility</guid>
      <dc:date>2026-06-04T16:46:36Z</dc:date>
      <dc:creator>Richard Petrie</dc:creator>
    </item>
    <item>
      <title>Corelight &amp; CrowdStrike Charlotte AI SOC Integration</title>
      <link>https://corelight.com/blog/crowdstrike-charlotte-ai-soc-integration</link>
      <description>&lt;p&gt;For years, SOC analysts have lived in a world of swivel-chair analysis. When an alert fires in an endpoint tool, the next step is almost always a manual pivot to a network console to see if the network reality matches the host behavior.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For years, SOC analysts have lived in a world of swivel-chair analysis. When an alert fires in an endpoint tool, the next step is almost always a manual pivot to a network console to see if the network reality matches the host behavior.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=8645105&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fcorelight.com%2Fblog%2Fcrowdstrike-charlotte-ai-soc-integration&amp;amp;bu=https%253A%252F%252Fcorelight.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>network detection response</category>
      <category>SOC</category>
      <category>Crowdstrike</category>
      <category>featured</category>
      <category>Corelight Investigator</category>
      <category>agentic triage</category>
      <pubDate>Wed, 03 Jun 2026 22:09:53 GMT</pubDate>
      <guid>https://corelight.com/blog/crowdstrike-charlotte-ai-soc-integration</guid>
      <dc:date>2026-06-03T22:09:53Z</dc:date>
      <dc:creator>Adam Pumphrey</dc:creator>
    </item>
    <item>
      <title>Corelight brings unique network data into Cisco Cloud Control</title>
      <link>https://corelight.com/blog/corelight-brings-unique-network-data-into-cisco-cloud-control</link>
      <description>&lt;h3&gt;&lt;em&gt;Integration provides vital data and detections so AI agents investigating security issues can understand the breach, risk, and required mitigation&lt;/em&gt;&lt;/h3&gt; 
&lt;p&gt;&lt;a href="https://www.corelight.com"&gt;Corelight&lt;/a&gt;, a leader in fueling the AI SOC, today announced that it is providing industry-leading data to power AI investigations of emerging threats through an integration of Corelight Open NDR into Cloud Control Studio. Cloud Control Studio is the design space within Cisco Cloud Control, Cisco’s unified platform for agentic IT operations, where customers can build AI agents and connect them to non-Cisco tools. This integration will provide security teams and the AI agents they employ in AI Canvas with detections and uniquely powerful data to effectively investigate security issues, improving the speed and accuracy of agentic security workflows.&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;&lt;em&gt;Integration provides vital data and detections so AI agents investigating security issues can understand the breach, risk, and required mitigation&lt;/em&gt;&lt;/h3&gt; 
&lt;p&gt;&lt;a href="https://www.corelight.com"&gt;Corelight&lt;/a&gt;, a leader in fueling the AI SOC, today announced that it is providing industry-leading data to power AI investigations of emerging threats through an integration of Corelight Open NDR into Cloud Control Studio. Cloud Control Studio is the design space within Cisco Cloud Control, Cisco’s unified platform for agentic IT operations, where customers can build AI agents and connect them to non-Cisco tools. This integration will provide security teams and the AI agents they employ in AI Canvas with detections and uniquely powerful data to effectively investigate security issues, improving the speed and accuracy of agentic security workflows.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=8645105&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fcorelight.com%2Fblog%2Fcorelight-brings-unique-network-data-into-cisco-cloud-control&amp;amp;bu=https%253A%252F%252Fcorelight.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>network security</category>
      <category>cybersecurity</category>
      <category>NDR</category>
      <category>Cisco</category>
      <category>threat hunting</category>
      <category>featured</category>
      <pubDate>Tue, 02 Jun 2026 18:05:00 GMT</pubDate>
      <guid>https://corelight.com/blog/corelight-brings-unique-network-data-into-cisco-cloud-control</guid>
      <dc:date>2026-06-02T18:05:00Z</dc:date>
      <dc:creator>Corelight</dc:creator>
    </item>
    <item>
      <title>How Data Quality Limits AI SOC Performance | Corelight</title>
      <link>https://corelight.com/blog/data-quality-limits-ai-soc-performance</link>
      <description>&lt;h2&gt;Low-quality data will prevent successful AI SOC transformation&lt;/h2&gt; 
&lt;p&gt;Defenders have long known that richer &lt;a href="https://corelight.com/resources/glossary/network-evidence"&gt;evidence&lt;/a&gt; improves security outcomes by enabling faster triage, deeper analysis, and more complete investigation. Although Corelight was founded on this premise, it’s been hard for us to quantify the impact of better network data - until now.&lt;/p&gt;</description>
      <content:encoded>&lt;h2&gt;Low-quality data will prevent successful AI SOC transformation&lt;/h2&gt; 
&lt;p&gt;Defenders have long known that richer &lt;a href="https://corelight.com/resources/glossary/network-evidence"&gt;evidence&lt;/a&gt; improves security outcomes by enabling faster triage, deeper analysis, and more complete investigation. Although Corelight was founded on this premise, it’s been hard for us to quantify the impact of better network data - until now.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=8645105&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fcorelight.com%2Fblog%2Fdata-quality-limits-ai-soc-performance&amp;amp;bu=https%253A%252F%252Fcorelight.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>data</category>
      <category>NDR</category>
      <category>SOC</category>
      <category>featured</category>
      <category>quality</category>
      <pubDate>Wed, 13 May 2026 21:49:28 GMT</pubDate>
      <guid>https://corelight.com/blog/data-quality-limits-ai-soc-performance</guid>
      <dc:date>2026-05-13T21:49:28Z</dc:date>
      <dc:creator>Gregory Bell</dc:creator>
    </item>
    <item>
      <title>5 Signs You Need to Upgrade Your Zeek Deployment | Corelight</title>
      <link>https://corelight.com/blog/upgrade-diy-zeek-deployment</link>
      <description>&lt;p&gt;You already know the immense value of open-source Zeek. It provides the absolute gold standard of &lt;a href="https://corelight.com/resources/glossary/network-evidence"&gt;network evidence&lt;/a&gt;, giving you the deep visibility required to defend your organization. You have the right strategic foundation, but the operational workload of managing a do-it-yourself (DIY) deployment at scale is likely draining your energy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;You already know the immense value of open-source Zeek. It provides the absolute gold standard of &lt;a href="https://corelight.com/resources/glossary/network-evidence"&gt;network evidence&lt;/a&gt;, giving you the deep visibility required to defend your organization. You have the right strategic foundation, but the operational workload of managing a do-it-yourself (DIY) deployment at scale is likely draining your energy.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=8645105&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fcorelight.com%2Fblog%2Fupgrade-diy-zeek-deployment&amp;amp;bu=https%253A%252F%252Fcorelight.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Zeek</category>
      <category>NDR</category>
      <category>featured</category>
      <pubDate>Tue, 05 May 2026 17:11:05 GMT</pubDate>
      <guid>https://corelight.com/blog/upgrade-diy-zeek-deployment</guid>
      <dc:date>2026-05-05T17:11:05Z</dc:date>
      <dc:creator>Matt Ellison</dc:creator>
    </item>
    <item>
      <title>The 7 Sins Killing Your SOC Efficacy (And Why NDR is the Cure) | Corelight</title>
      <link>https://corelight.com/blog/deadly-sins-of-ndr</link>
      <description>&lt;p&gt;Network Detection and Response (&lt;a href="https://corelight.com/resources/glossary/ndr-network-detection-and-response"&gt;NDR&lt;/a&gt;) is a glorious tool for spotting the stuff that slips past the velvet ropes. The weird lateral movement. The "why is Finance talking to a printer in Moldova" moment. The internal reconnaissance that looks harmless until it's suddenly not.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Network Detection and Response (&lt;a href="https://corelight.com/resources/glossary/ndr-network-detection-and-response"&gt;NDR&lt;/a&gt;) is a glorious tool for spotting the stuff that slips past the velvet ropes. The weird lateral movement. The "why is Finance talking to a printer in Moldova" moment. The internal reconnaissance that looks harmless until it's suddenly not.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=8645105&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fcorelight.com%2Fblog%2Fdeadly-sins-of-ndr&amp;amp;bu=https%253A%252F%252Fcorelight.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>network security</category>
      <category>cybersecurity</category>
      <category>logs</category>
      <category>NDR</category>
      <category>SOC</category>
      <category>firewall</category>
      <category>featured</category>
      <category>AI</category>
      <pubDate>Thu, 30 Apr 2026 17:58:17 GMT</pubDate>
      <guid>https://corelight.com/blog/deadly-sins-of-ndr</guid>
      <dc:date>2026-04-30T17:58:17Z</dc:date>
      <dc:creator>Josh Porto</dc:creator>
    </item>
    <item>
      <title>RSAC 2026: Lessons in Cyber Resilience | Corelight</title>
      <link>https://corelight.com/blog/rsac-2026-lessons-in-resilience</link>
      <description>&lt;p&gt;The halls of RSAC 2026 were buzzing with a singular question: &lt;em&gt;"How do we defend an ecosystem that is moving faster than we can think?"&lt;/em&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The halls of RSAC 2026 were buzzing with a singular question: &lt;em&gt;"How do we defend an ecosystem that is moving faster than we can think?"&lt;/em&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=8645105&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fcorelight.com%2Fblog%2Frsac-2026-lessons-in-resilience&amp;amp;bu=https%253A%252F%252Fcorelight.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>network security</category>
      <category>cybersecurity</category>
      <category>featured</category>
      <category>RSAC</category>
      <pubDate>Thu, 23 Apr 2026 22:33:31 GMT</pubDate>
      <guid>https://corelight.com/blog/rsac-2026-lessons-in-resilience</guid>
      <dc:date>2026-04-23T22:33:31Z</dc:date>
      <dc:creator>Ed Smith</dc:creator>
    </item>
    <item>
      <title>Energy Cybersecurity in the Age of Claude Mythos | Corelight</title>
      <link>https://corelight.com/blog/defending-energy-infrastructure-in-the-age-of-mythos-corelight</link>
      <description>&lt;p&gt;The Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) has released its first &lt;a href="https://www.energy.gov/documents/ceser-strategic-plan2026-2030"&gt;five-year strategic plan&lt;/a&gt;, following the broader national cybersecurity strategy. It’s coming at a time when the &lt;a href="https://corelight.com/solutions/industry/energy"&gt;energy cybersecurity&lt;/a&gt; landscape is changing quickly, in some cases faster than operators can realistically keep up.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) has released its first &lt;a href="https://www.energy.gov/documents/ceser-strategic-plan2026-2030"&gt;five-year strategic plan&lt;/a&gt;, following the broader national cybersecurity strategy. It’s coming at a time when the &lt;a href="https://corelight.com/solutions/industry/energy"&gt;energy cybersecurity&lt;/a&gt; landscape is changing quickly, in some cases faster than operators can realistically keep up.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=8645105&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fcorelight.com%2Fblog%2Fdefending-energy-infrastructure-in-the-age-of-mythos-corelight&amp;amp;bu=https%253A%252F%252Fcorelight.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>network security</category>
      <category>cybersecurity</category>
      <category>featured</category>
      <category>Mythos</category>
      <category>Department of Energy</category>
      <category>DOE</category>
      <category>CESER</category>
      <pubDate>Fri, 17 Apr 2026 20:36:34 GMT</pubDate>
      <guid>https://corelight.com/blog/defending-energy-infrastructure-in-the-age-of-mythos-corelight</guid>
      <dc:date>2026-04-17T20:36:34Z</dc:date>
      <dc:creator>Gregory Bell</dc:creator>
    </item>
  </channel>
</rss>
