SAN FRANCISCO, Sept. 15, 2026 /PRNewswire/ -- Corelight, a leader in enabling the defensible AI SOC, today announced new solutions to accelerate the adoption of the AI SOC without surrendering the transparency, auditability, and control that network defense demands. Corelight released the Agent Builder Library and Natural Language Query to best leverage the speed and functionality of AI and address the state of constant vulnerability most enterprises now face. Corelight is also expanding its detection coverage beyond identifying which AI applications are in use to catching AI supply-chain compromise, anomalous AI activity, and stealth command-and-control (C2) and exfiltration — all feeding directly into the same expert-authored, auditable investigation logic behind its AI capabilities.
Attackers are using AI models to accelerate vulnerability discovery and exploitation, compressing the window defenders have to respond. While typical enterprise patching cycles can still run from 60 to 150 days, the median time to exploit has fallen to roughly five days. In addition, with Mythos-class AI models, defenders are expecting to see vulnerabilities exploited before there is broad knowledge that there is even a hole to be patched. Faster patching simply is not the answer – AI-speed attacks require AI-speed defense. However, widespread adoption of AI in the SOC is progressing slower than attacker adoption of AI, held back by two persistent barriers: a network expertise gap and a query language expertise gap. Corelight's latest release eliminates both.
"The instinct is to fight AI-speed attacks with AI-speed defense, and that's right. But speed without expertise is just fast guessing," said Vijit Nair, senior vice president of product at Corelight. "We've packaged a decade of network forensics knowledge into building blocks that any AI agent can execute, whether it's ours or the customer's own. The result is an AI investigation that's transparent enough for a skeptical analyst to verify line-by-line, accessible enough for a day-one hire to use immediately, and operational enough to put these agentically validated, pre-triaged threats directly in front of the human as quickly as possible."
Corelight has spent more than a decade turning ground-truth network evidence into the standard that the most attacked, hardened security teams rely on. Earlier this year, Corelight also introduced Agentic triage, category-first AI capabilities that help modern SOCs automate the most repetitive tasks consuming security teams, dramatically improving analyst efficiency and speed while also building trust through complete transparency. This launch extends that same expertise into tools that let every SOC operate as elite network defenders, ready to combat the most challenging cyber threat in history.
- Corelight Agent Builder Library — Tackling the expertise barrier, Corelight provides a structured set of triage playbooks, field explanations, entity-pivoting guides, and investigation decision trees, distilled from more than a decade of Corelight's network forensics expertise. Because the logic is deterministic and documented rather than probabilistic, it is fully exportable — security teams can bring it into their own AI agents, SOAR workflows, or private LLM environments, including air-gapped and classified networks with no cloud connectivity.
- Natural Language Query (NLQ) — Addressing the query syntax barrier, Corelight lets analysts ask plain-English questions about network evidence and receive working, LogScale queries that are automatically validated and executed against their data. Orchestrated AI sub-agents analyze each question, build a query plan, and return results with full chain-of-thought reasoning visible to the analyst. The generated query is editable so analysts can learn from the construction and refine as needed – removing the need to learn specialized syntax before investigating.
"Security teams are increasingly investigating the use of AI to combat the accelerating speed of threat actors who have been early adopters of the technology," said Andrew Braunberg, principal analyst, Omdia. "The ability to automate security workflows are quickly becoming expected capabilities in SecOps solutions but the tools that become widely adopted in the SOC will need to do more than just automate, they will need to document, evaluate, and explain. Inspectable logic that can run outside the vendor's cloud isn't a nice-to-have anymore; for a lot of buyers, especially in regulated and air-gapped environments, it's a primary evaluation criterion."
Unlike AI investigation tools that operate as opaque scoring engines, every Corelight-generated verdict is traceable to the specific playbook invoked, the behavioral signals that triggered it, and the evidence that supports it — a distinction critical to both to skeptical analysts and to regulators. The capabilities are designed to support documented, defensible incident response under frameworks such as NIS2, DORA, SEC disclosure rules, and CMMC 2.0.
From Shadow AI Visibility to AI Threat Detection and Behavioral Defense
Alongside these AI investigation capabilities, Corelight is expanding beyond identifying which AI applications are in use to detecting when AI-related activity becomes a security threat. New AI threat detections identify known AI supply-chain compromise indicators, suspicious AI gateway and provider activity, attacks against exposed AI infrastructure, and anomalous AI application behavior. Combined with expanded behavioral analytics for command-and-control and data exfiltration, Corelight gives defenders visibility across both emerging AI threats and the broader attacker path.The expansion adds three capabilities aimed at threats that don't leave a signature behind.
- Detect known AI threats — Corelight identifies AI supply-chain compromise indicators, known exfiltration infrastructure, suspicious AI gateways and providers, and reconnaissance or exploitation attempts against exposed AI endpoints.
- Detect anomalous AI activity — Application anomaly detection surfaces new or unusual AI usage and behavior that deviates from established patterns, helping analysts identify potentially compromised or misused AI applications even when no known signature exists.
- Detect stealth C2 and exfiltration — Corelight combines 31-day subnet-level destination history with per-host upload baselining to surface connections to never-before-seen countries and unusual outbound data transfers, exposing C2, staging, and data theft that static blocklists or thresholds can miss.
Every signal generated by the expanded Anomaly Engine feeds directly into the Corelight Agent Builder Library's playbooks and into Agentic Triage, so behavioral detections don't just fire an alert — they trigger the same expert-authored investigation logic that produces an auditable, evidence-backed verdict.
For more information, please visit https://corelight.com/blog/defensible-ai-soc-mythos-era.
About Corelight
Corelight transforms network and cloud activity into evidence that security teams use to proactively hunt for threats, accelerate response to incidents, gain complete network visibility, and create powerful analytics. Corelight's customers include Global 2000 companies, major government agencies, and large research universities. Based in San Francisco, Corelight is an open-core security company founded by the creators of Zeek®, the widely used open-source network security technology. For more information, visit www.corelight.com.
SOURCE Corelight