With Corelight Sensor v29.2, generally available September 16, 2026, your team gains the ability to behaviorally detect and disrupt multi-stage intrusions, govern AI usage across your network without decryption, and deploy sensors in minutes instead of hours. This post covers what’s new and how it accelerates your security operations.
Corelight continues to give your team behavioral anomaly visibility across multi-stage intrusions, from credential theft and lateral movement through command-and-control to data exfiltration. Three new anomaly models learn what’s normal for your environment and surface deviations, with no static thresholds to configure and no manual tuning required.
Together with credential theft detections and earlier anomaly detections released in v29.1, these capabilities enable your SOC to track an intrusion from its first foothold to its final objective entirely through behavioral analysis. Your team spends less time correlating disconnected alerts and more time making decisions.
Your security team can now see exactly which AI tools are in use, who is using them, and where your greatest exposure lies, without decryption or endpoint agents. Corelight passively identifies over 80 AI services directly from network traffic and assigns each service category a risk level.
New in v29.2 are two purpose-built dashboards, AI Governance and Shadow AI, delivering immediate operational visibility. Coupled with the new anomaly detection for applications, these dashboards alert you to new and likely unauthorized AI application usage. Your team can answer critical governance questions in seconds: Which AI tools are active? Which network segments have the highest adoption? Which connections violate policy? Which users are connecting to high-risk foreign providers?
This passive approach means your team gains AI governance visibility today, without deploying new infrastructure or disrupting existing workflows.
Corelight Sensor v29.2 expands your team’s ability to detect FRP and Ligolo-ng protocol tunneling that can be used for command-and-control communication, lateral movement, and data exfiltration. New behavioral detections identify protocol abuse across FRP and Ligolo-ng use. Because these detections are built on Zeek behavioral scripting rather than only signatures, they work regardless of which specific approach an attacker uses, providing durable coverage that doesn’t require constant rule updates.
Corelight already delivers encrypted traffic analysis, including SSH inference capabilities. In this release, machine learning bolsters these inferences, significantly improving visibility into SSH traffic and the accuracy of SSH inference without the need to decrypt network traffic.
Corelight Sensor v29.2 streamlines sensor operations so your team spends less time on infrastructure and more time on security.
Low-touch provisioning delivers a sensor that goes from power-on to Fleet-registered in five interactions, reducing the need for manual configuration. Anyone on your team can deploy a sensor, and no CLI expertise, SSH sessions, or multi-step workflows are needed.
Fleet CNSA 2.0 mode enforces government-grade cryptography across your entire sensor fleet with a single setting. Federal and regulated teams meet CNSA 2.0 mandates without per-sensor configuration.
ASG sensor inventory gives you individual visibility into auto-scaling group sensors, with stale instances automatically hidden, keeping your operational view clean and accurate.
Corelight Sensor v29.2 delivers new capabilities that get evidence into your analysts’ hands faster:
Corelight Sensor v29.2 gives your team the behavioral detection, AI governance visibility, and operational simplicity to stay ahead of today’s threats. Full release notes are available in your Corelight console or via docs.corelight.cloud.