What powers your AI SOC?
The economics of cyberattacks have changed permanently. The time-to-exploit window that security programs were built for — measured in months — has collapsed to hours. Security leaders building an AI SOC to combat the new reality face a choice. Model or data? What really matters?
Join us in our booth theater
Choice of Model vs. Choice of Data: What Actually Powers an AI SOC?
What's more important for the AI SOC, choice of model or choice of data? To explore this question, we asked specialized agents to compete in a realistic Capture the Flag (CTF) exercise inspired by a range of real-world attack scenarios, and we ran dozens of simulated competitions. Come hear Corelight Co-Founder Greg Bell talk about our surprising conclusions, along with techniques for increasing the inference ceiling of your AI SOC.

When:
- Tuesday, August 4, 5:00pm PT
- Wednesday, August 5, 10:00am & 2:00pm PT
Where:
- Corelight Booth #3940 (Business Hall: Bayside A-D, Mandalay Bay Convention Center)
- No special pass required, any conference pass holder can access this session in our booth
Network Visibility Stacks the Deck Against Mythos
How Corelight gives defenders the ground truth to catch what prevention misses
Mythos-class models are changing the economics of finding vulnerabilities. What took skilled teams weeks will now happen at machine speed, across more of the stack than any human effort could cover. The result won’t be one dramatic breach. It will be a steady storm of vulnerabilities and bugs surfacing faster than teams can patch.
You can’t out-patch that curve. But attackers still have to move through your network. Every attack generates traffic on the wire, and that evidence doesn’t depend on knowing the vulnerability in advance. Join us to hear how network visibility is the defense that scales and stacks the deck against Mythos-class AI models.

When:
- Wednesday, August 5th: 2:30pm PT
- Thursday, August 6th: 11:30am PT
Where:
- Corelight Booth #3940 (Business Hall: Bayside A-D, Mandalay Bay Convention Center)
- No special pass required, any conference pass holder can access this session in our booth
Navigating Volt Typhoon with NDR
As sophisticated threat actors like Volt Typhoon shift toward "living off the land" tactics, traditional perimeter defenses are being rendered blind. When attackers use your own legitimate admin tools against you, blending into the noise is their ultimate weapon. This session breaks down how Network Detection and Response (NDR) delivers the deep visibility required to expose hidden, state-sponsored activity inside enterprise networks before the damage is done.

When:
- Wednesday, August 5, 11:00am PT
- Thursday, August 6, 11:00am PT
Where:
- Corelight Booth #3940 (Business Hall: Bayside A-D, Mandalay Bay Convention Center)
- No special pass required, any conference pass holder can access this session in our booth
Pass discount:
Get our Pass discount:
$200 off Briefings Pass OR $100 off Business Pass current pricing
Discount code: CORELIGHT
Book a demo
Stop by our booth to explore how Corelight's agentic triage automates threat identification and improves triage time by 10x today.
Grab some gear
Stay for a demo, get cool stuff.
Corelight Open NDR helps defend Black Hat event
Year four—and we’re still thrilled to join forces with the Black Hat NOC and other distinguished best of breed vendors. We’ll be helping defend the conference network with our NDR technology alongside Arista Networks, Cisco Secure, Jamf, Lumen, and Palo Alto Networks.
Check out our latest blog NOC posts:
Black Hat Asia 2026: Everything from cat feeders to solar farms
Black Hat USA 2025: Back in the NOC: A familiar mission, new crew
Black Hat NOC: Findings from Europe & Thoughts for Asia 2024
Detections and Findings using Corelight in the Black Hat Asia NOC 2023
Tuesday, August 4 |
|
|
|---|---|---|
|
5:00 PM |
|
Choice of Model vs. Choice of Data: What Actually Powers an AI SOC? |
|
6:00 PM |
|
Corelight Demo |
Wednesday, August 5 |
|
|
|---|---|---|
|
10:00 AM |
|
Choice of Model vs. Choice of Data: What Actually Powers an AI SOC? |
|
11:00 AM |
|
Navigating Volt Typhoon with NDR |
|
11:30 AM |
|
Unifying SSE and Open NDR: Full-Spectrum Visibility and Rapid Response for the Hybrid Enterprise |
|
2:00 PM |
|
Choice of Model vs. Choice of Data: What Actually Powers an AI SOC? |
|
2:30 PM |
|
Network Visibility Stacks the Deck Against Mythos |
|
3:30 PM |
|
Precision Data from OT to IT and All the Way to the AI SOC |
|
4:00 PM |
|
Network Evidence: A Perfect AI SIEM Compliment |
Thursday, August 6 |
|
|
|---|---|---|
|
9:30 AM |
|
Endace and Corelight: Always-on Packet Capture - the Ultimate Network Forensics for the AI SOC |
|
10:00 AM |
|
ATT&CKing Back: Unified Detection with Corelight & Elastic, Turning Network Traffic into Rocket Fuel for the AI SOC |
|
11:00 AM |
|
Navigating Volt Typhoon with NDR |
|
2:30 PM |
|
Network Visibility Stacks the Deck Against Mythos |
See how Corelight integrates with your existing toolstack, including:
Unlock your AI-powered SOC
Corelight’s Open NDR Platform secures the networks the world depends on with unified visibility across network and cloud environments, autonomous identification of evolving threats with AI-powered multi-layered detections, and threat containment with integrated response.
