Deployment options
Your security architecture, your rules. Corelight offers complete deployment freedom across cloud, virtual, software, and physical sensors—giving you zero-friction integration in SaaS, air-gapped, or hybrid environments.
Choosing the right deployment model for your environment
The Corelight Open NDR Platform offers the flexibility to select the optimal deployment model for your specific infrastructure and allows you to adapt your security posture as your requirements evolve.
Deployment options designed to fit any SOC architecture
Resilient, high-performance infrastructure options to run anywhere, from air-gapped data centers to multicloud environments.
On-prem
Ideal for organizations requiring on-premises or air-gapped solutions, and for those who prefer to feed raw network data and detections into SIEM, data lake, or XDR solutions, Corelight’s sensor-only option ensures data remains private and audit-ready within your trusted perimeter. Our physical and software sensors combine six legacy security functions into a single high-fidelity source of truth and are built to handle demanding network environments at 100+ Gbps scale, with built-in support for merging high-volume traffic.
SaaS
Corelight's cloud-delivered platform gives you flexibility in how you deploy and consume network evidence. Use cloud-managed sensors with Fleet Manager to simplify sensor operations and export rich network evidence directly to your existing SIEM or data lake. Or go further with Corelight Investigator — a complete NDR platform that adds AI/ML detections, generative and agentic AI assistance, and unified investigation workflows, consolidating IDS, PCAP, NSM, and file analysis into a single experience with flexible storage options.
Hybrid
For organizations that require a blended deployment option, our hybrid offering provides the agility to secure a complex distributed environment. Maintain sensitive data analysis on-site while leveraging cloud resources for unified detection and investigations across distributed environments. Hybrid licensing supports mixed environments and ensures that the same Zeek®-based context is available everywhere.
Corelight Sensor options
Unparalleled control and defensibility for on-prem and air-gapped environments
On-premises or air-gapped deployments offer complete control by keeping data and analytics within your physical environment. Choose hardware appliances or software-based sensors to passively ingest mirrored network traffic without impacting performance
High-fidelity visibility in virtualized environments
Leverage your existing infrastructure for a cost-effective, flexible solution. Virtual deployments utilize software-based sensors on your virtual machines running on Microsoft Hyper-V and VMware, reducing hardware costs and physical footprint. This model offers high-fidelity network visibility in virtualized environments without dedicated hardware, supporting incident response, threat detection, and compliance. It is an ideal choice for organizations with robust virtualization platforms seeking scalable, efficient network visibility.
Unified visibility across your entire cloud ecosystem
Lightweight cloud-native sensors for AWS, Azure, and GCP capture cloud traffic and flow logs. Corelight provides a unified, standard Zeek log format that simplifies security investigations and integrations with SIEM and SOAR tools. Scalable, usage-based licensing is ideal for dynamic cloud environments, streamlining security management and giving you a single, coherent view of your security posture across disparate cloud environments.
Turn raw flow logs into high-fidelity security evidence
Flow log sensors transform raw cloud and network flow data into structured Zeek logs by ingesting from devices or storage systems, such as AWS S3 buckets and NetFlow sources. This delivers standardized, high-fidelity network evidence that integrates seamlessly with your existing cloud and on-prem security stack.
Manage large sensor deployments with Fleet Manager
Fleet Manager acts as the centralized command center for your global network security infrastructure, giving you a commanding view of network health and performance across thousands of sensors. Rapidly deploy and tune detections, machine learning models, and custom YARA rules in minutes, all while streamlining workflows.
Breaches are inevitable; confident response is not
Our NDR Buyer's Guide provides the clarity to select the right platform and master crisis decision-making.
Seamless integration with your environment
The Corelight ecosystem delivers an open, flexible architecture designed to secure sprawling networks by integrating high-fidelity network evidence seamlessly into any security stack. With native integrations across SIEM, XDR, Cloud, and identity platforms, Open NDR eliminates operational silos and simplifies adoption without the constraints of proprietary lock-in.
Unified visibility with extended context
Extend high-fidelity network evidence with integrated host, identity, and vulnerability data from partners like CrowdStrike and Microsoft. Leverage the connectors to periodically query APIs for near-real-time host attributes and CVE enrichment directly within sensor logs.
Refined investigative workflow
Refine your SOC operations by delivering network evidence directly into your SIEM / XDR through built-in connectors while dramatically reducing network log volume and preserving critical security insights.
Confident and rapid response
Mount a decisive defense with integrated response actions across identity platforms, firewalls, and ticketing systems. Respond immediately from Corelight Investigator or create new cases for further investigation.
Maximize ROI with services and training from Corelight
Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.
-
Accelerate implementation and time to value with health checks
-
Precision engineering for detection calibration and customization
-
Expert-led training and education services
FAQ
What deployment options does Corelight offer?
Corelight provides hardware appliances for on-premises deployments, virtual sensors for VMware and Hyper-V environments, cloud sensors for AWS, Azure, and Google Cloud, software sensors for Linux-based systems, and flow log sensors that transform raw flow logs into structured Zeek logs.
Can Corelight sensors be deployed in both on-premises and cloud environments?
Yes, Corelight sensors support deployment in on-premises networks (using hardware or virtual sensors) and in public cloud environments (using cloud sensors for AWS, Azure, and Google Cloud).
What is required to deploy a Corelight virtual sensor?
A Corelight virtual sensor requires a supported hypervisor (such as VMware ESXi or Hyper-V), two virtual network interfaces (one for management, one for monitoring), and access to mirrored network traffic via port mirroring or a packet broker.
How are Corelight sensors managed after deployment?
Sensors can be managed locally via console or remotely using Fleet Manager, which provides centralized configuration, monitoring, and policy deployment for all sensor types.
Can Corelight sensors be deployed in air-gapped or offline environments?
Yes, Corelight hardware and virtual sensors can be deployed and updated in air-gapped or offline environments using offline seeding and manual license management processes.
What is Corelight’s hybrid cloud deployment, and when should I use it?
Corelight hybrid cloud deployment allows you to monitor traffic across both on-premises and cloud environments. By combining on-site physical or virtual sensors with cloud-native sensors, you achieve unified network evidence, consistent detections, and a single source of truth for investigations across their infrastructure. This model is ideal for organizations transitioning to the cloud or running multi-environment workloads.
What is Corelight’s multicloud deployment, and why is it important?
Multicloud deployment enables monitoring of traffic across AWS, Azure, and GCP simultaneously. Lightweight cloud-native sensors capture mirrored traffic, VPC flows, and network metadata, providing a consistent format and unified detections across providers. This ensures your SOC maintains full visibility, regardless of where workloads run.
Can multicloud deployments integrate with my existing security stack?
Yes. Corelight cloud sensors integrate natively with SIEM, SOAR, and threat intelligence platforms. This enables alerts and network evidence from all clouds to flow into existing workflows, facilitating rapid triage, investigations, and automated responses.
How does Corelight simplify scaling in multicloud environments?
Cloud-native sensors are lightweight and easy to deploy. Licensing is consumption-based, allowing organizations to quickly scale monitoring across multiple cloud accounts or regions without requiring complex infrastructure changes.