VOLT TYPHOON WARNING
Combat advanced attacks
Volt Typhoon is compromising critical infrastructure by exploiting unmanaged appliances and evading EDR.
Your best defense against these and other advanced attacks is your network.

- How Volt Typhoon and other advanced attacks use living-off-the-land (LOTL) techniques for persistence and lateral movement
- CISA’s recommendation about implementing strong network monitoring and visibility to combat advanced TTPs such as these
- How NDR delivers on these recommendations to identify and neutralize attacks
EDR alone is not sufficient
Strengthen your defenses with Corelight's multi-layered detection strategy to identify and counter threats that evade traditional EDR solutions. Mission-ready network detection and response (NDR) solutions such as Corelight’s complement EDR to provide unprecedented visibility to detect advanced TTPs.
EDR SHORTCOMING
- Endpoint agents can be misconfigured
- EDR can be disabled or bypassed by attackers
- EDR struggles to see unmanaged assets
CORELIGHT’S NDR SOLUTION
- Enhances EDR with
high network visibility - Prioritizes aggregated threat alerts for multi-layered detection
- Expands visibility into unmanaged assets with Zeek®’s industry-standard metadata—through the Corelight Entity Collection

The critical way to detect and disrupt Volt Typhoon is with the high visibility you only get from the network.
ROB JOYCE, Corelight Advisor
Former NSA Cybersecurity Director
The network is the crucial component
SOC teams need comprehensive network data to defend against attacks. Corelight combines industry-leading Zeek network metadata, multi-layered detections, packet capture (PCAP), and file analysis (YARA) for the best approach to network-driven defense. Disrupt attacks, address gaps within your security stack, and reduce risk to your organization with Corelight's NDR solution.
