Corelight Bright Ideas Blog: NDR & Threat Hunting Blog

Sensor v29.2: Behavioral Detection & AI Governance | Corelight

Written by Cynthia Gonzalez | Sep 16, 2026, 3:36:55 PM

With Corelight Sensor v29.2, generally available September 16, 2026, your team gains the ability to behaviorally detect and disrupt multi-stage intrusions, govern AI usage across your network without decryption, and deploy sensors in minutes instead of hours. This post covers what’s new and how it accelerates your security operations.

Gain visibility across the attack path

Corelight continues to give your team behavioral anomaly visibility across multi-stage intrusions, from credential theft and lateral movement through command-and-control to data exfiltration. Three new anomaly models learn what’s normal for your environment and surface deviations, with no static thresholds to configure and no manual tuning required.

  1. Exfiltration detection baselines each host’s upload patterns and alerts when data leaves your network unexpectedly.
  2. Application usage detection learns which applications normally communicate between your network segments and flags unusual tools the moment they appear.
  3. Destination country detection identifies connections to previously unseen geographic locations, giving your team early warning of potential C2 or exfiltration activity.

Together with credential theft detections and earlier anomaly detections released in v29.1, these capabilities enable your SOC to track an intrusion from its first foothold to its final objective entirely through behavioral analysis. Your team spends less time correlating disconnected alerts and more time making decisions.

Govern AI usage across your network

Your security team can now see exactly which AI tools are in use, who is using them, and where your greatest exposure lies, without decryption or endpoint agents. Corelight passively identifies over 80 AI services directly from network traffic and assigns each service category a risk level.

New in v29.2 are two purpose-built dashboards, AI Governance and Shadow AI, delivering immediate operational visibility. Coupled with the new anomaly detection for applications, these dashboards alert you to new and likely unauthorized AI application usage. Your team can answer critical governance questions in seconds: Which AI tools are active? Which network segments have the highest adoption? Which connections violate policy? Which users are connecting to high-risk foreign providers?

This passive approach means your team gains AI governance visibility today, without deploying new infrastructure or disrupting existing workflows.

Detect lateral movement and C2 tunneling

Corelight Sensor v29.2 expands your team’s ability to detect FRP and Ligolo-ng protocol tunneling that can be used for command-and-control communication, lateral movement, and data exfiltration. New behavioral detections identify protocol abuse across FRP and Ligolo-ng use. Because these detections are built on Zeek behavioral scripting rather than only signatures, they work regardless of which specific approach an attacker uses, providing durable coverage that doesn’t require constant rule updates.

Sharpen SSH analytics with machine learning

Corelight already delivers encrypted traffic analysis, including SSH inference capabilities. In this release, machine learning bolsters these inferences, significantly improving visibility into SSH traffic and the accuracy of SSH inference without the need to decrypt network traffic.

Deploy and manage sensors with zero friction

Corelight Sensor v29.2 streamlines sensor operations so your team spends less time on infrastructure and more time on security.

Low-touch provisioning delivers a sensor that goes from power-on to Fleet-registered in five interactions, reducing the need for manual configuration. Anyone on your team can deploy a sensor, and no CLI expertise, SSH sessions, or multi-step workflows are needed.

Fleet CNSA 2.0 mode enforces government-grade cryptography across your entire sensor fleet with a single setting. Federal and regulated teams meet CNSA 2.0 mandates without per-sensor configuration.

ASG sensor inventory gives you individual visibility into auto-scaling group sensors, with stale instances automatically hidden, keeping your operational view clean and accurate.

Accelerate forensic investigations

Corelight Sensor v29.2 delivers new capabilities that get evidence into your analysts’ hands faster:

  • SSH inference (GA) classifies all SSH session types without decryption, giving your team visibility into encrypted traffic.
  • Direct PCAP retrieval lets analysts download packet captures directly from SIEM alerts with SSO authentication, even when the sensor is offline.
  • Smart PCAP trigger by geo enables geography-based capture, so analysts collect targeted forensic evidence automatically.
  • Batch export now supports data aggregation logs, giving data lake customers efficient access to high-level network intelligence.

Upgrade to v29.2

Corelight Sensor v29.2 gives your team the behavioral detection, AI governance visibility, and operational simplicity to stay ahead of today’s threats. Full release notes are available in your Corelight console or via docs.corelight.cloud.