Corelight Collections
Uncover additional insights with Corelight expert-curated detection and enrichment packages.
Curated scripts for detection and visibility
Illuminate evasive and advanced threats with six targeted Collections offering out-of-the-box insights and detections in network protocols, encrypted traffic, entities, and ICS/OT. These collections help detect C2, lateral movement, port scanning, cryptomining, tunneling, domain generation algorithms (DGA), and more. Built on Zeek®, each Collection evaluates how traffic actually behaves, then feeds its findings into Corelight's evidence and analytics layer.
Empower your team with purpose-built detections curated by Corelight
Every Collection targets a specific security problem, from command and control to industrial protocols. Each detection arrives linked to the network evidence that produced it, so analysts begin an investigation with the underlying logs, files, and session context already in hand.
Corelight Collections
Core Collection
![]()
Curated insights from the Zeek® community, plus tools that lower total cost of ownership from Corelight. Detect cryptomining, port scans, lateral movement, and more with analytics built on Zeek community contributions and optimized by Corelight. The Core Collection also layers additional context into Open NDR Platform evidence and applies data controls that trim SIEM ingestion volume and cost.
-
Accelerate investigations with standards like JA3(S) and Community ID
-
Lower SIEM data ingestion and related costs
-
Optimize sensor performance to do more with less
Command and Control (C2) Collection
![]()
Discover if an attacker is remotely controlling assets on your network. Find DGA, DNS, and ICMP tunneling. Corelight’s C2 Collection has over 50 unique insights and detections that illuminate command and control activity. Battle-tested by some of the world’s most sophisticated organizations, this collection covers known C2 toolkits and MITRE ATT&CK® C2 techniques to find novel attacks.
-
Catch attacker tunnels camouflaged as normal traffic
-
Find Cobalt Strike, Empire, Metasploit, and other common tools
-
Extend MITRE ATT&CK coverage with 50+ unique C2 detections and insights
Encrypted Traffic Collection
![]()
See and counter threats, even those hidden by encryption, without decryption. Getting visibility into encrypted traffic can seem impossible, but ignoring it gives attackers an ideal hiding place. The Encrypted Traffic Collection turns network data flows into rich evidence and actionable insights, without decryption, so you can understand and mitigate risk. By combining observable elements, like timestamps and packet sizes, with known behavior of protocols, the collection offers a practical approach to visibility that helps you see and act on what matters. It also avoids the heavy financial, privacy, and performance costs of decryption.
-
Find advanced attacks hiding in encrypted traffic
-
Gain visibility into SSL, SSH, RDP, DNS, and VPN traffic
-
Highlight misconfigurations that expose data
Entity Collection
![]()
Network asset discovery and inventory. Track everything connected to your network and build a strong foundation for discovery, profiling, and inventory. Asset inventory management is notoriously difficult in large enterprise environments, where an ever-changing inventory of unknown, unmanaged entities traverses the network. The Corelight Entity Collection gives security teams powerful identification capabilities for applications, devices, services, certificates, hosts, and more, helping them map and defend their environment more comprehensively. The Entity Collection also delivers visibility into specific entity activity, for example, revealing all hosts that have used SSH in the past 24 hours. This capability helps your team determine whether high-value assets have been compromised by insider threats or adversaries leveraging stolen SSH credentials.
-
Identify known apps and new local subnets
-
Discover activity related to hosts, devices, services, names, certs, domains, and users
-
See current entity activity and track it over time
ICS/OT Collection
![]()
Enhanced visibility and security for ICS/OT devices and protocols. Lack of visibility can create security blind spots in any environment, from a factory floor to an enterprise IT network. Corelight offers a visibility solution for identifying and monitoring the most common Industrial Control System (ICS) and Operational Technology (OT) protocols, improving defense across diverse environments. Use the ICS/OT Collection to identify devices and capture evidence related to ICS/OT protocols, yielding greater visibility and faster incident response times. Monitor uncommon network behavior, such as an HVAC system interacting with a server, and react more quickly to risks by identifying anomalies in enterprise and operational network traffic in real time.
-
Identify and log ICS/OT protocols like BACnet, DNP3, EtherCAT, Modbus, and more
-
Discover activity related to HVAC, security cameras, smart lighting, and access control systems
-
Built on contributions from the Cybersecurity and Infrastructure Security Agency (CISA)
Analyzers Collection

Enhanced visibility into additional specific network protocols. The Analyzers Collection includes expanded visibility into over ten fundamental network protocols. This collection helps to remove security blind spots in the network. Corelight enables security teams to identify and monitor core and common network protocols to enable defense against threats hiding in this traffic. These protocols facilitate secure communication, device discovery, remote access, logging, messaging, and resource sharing across networks, found in specific use cases like VPNs (OpenVPN, WireGuard, IPsec), directory services (LDAP), file sharing (SMB), or event notifications (SSDP, GENA). With the Analyzers Collection, teams can identify protocol-based network traffic anomalies in real time and respond to risks more quickly.
-
Identify and log network protocols, including LDAP, IPsec, SMB, and more
-
Discover activity related to lateral movement in administrative, security, and file-sharing traffic
-
Confirm that only authorized devices and users are utilizing specific protocols, reducing the risk of unauthorized access to sensitive resources like LDAP directories or SMB shares
Get detections and enrichments from the data you already have
Correlated network evidence
Each collection transforms raw traffic into structured, actionable intelligence, delivering high-fidelity detections and rich enrichment grounded in forensic-grade network evidence you can trust. The result is sharper detections, deeper context, and faster investigations.
Elevate AI/ML threat detection
Expand your detection coverage from day one with added command and control (C2) detections and MITRE ATT&CK TTP coverage. Corelight Collections work together with signatures, IOCs, YARA, and machine learning directly on-sensor to deliver multi-layered, high-fidelity detections. The payoff: Smarter data, higher confidence detections, and faster response.
Sharper incident response
When an incident breaks, Corelight Collections enrich your data and tie every detection directly to the network evidence behind it. Analysts can pivot from alert to full context in seconds, not hours, cutting response times by up to 95%. The result is sharper investigations and cases you can close with confidence.
Enrich your entire multi-layered detection architecture
Network Security Monitoring with Zeek
Built on Zeek. Corelight Collections start with Zeek, the open-source engine that turns raw traffic into forensic-grade telemetry. Every detection maps back to structured, richly correlated logs, so analysts can pivot from alert to evidence using a shared connection identifier (UID), with no guesswork and no dead ends.
Intrusion Detection
Corelight Collections expose evasive threats through behavioral analytics and deep protocol parsing, while an integrated Suricata IDS adds a layer of confidence by matching traffic against rulesets and signatures to catch known threats. Every Suricata and Collections alert is pre-correlated with Zeek logs via a shared connection identifier, making it easy to pivot to network evidence in a single click and accelerating incident response.
Threat Intelligence
Threat Intelligence provides curated, high-fidelity IOCs to reinforce the detections provided by the Corelight Collections as part of the multi-layered detection capabilities. Matched against live and historical traffic in real time, this ground-truth network evidence lets you validate threats faster, hunt retrospectively, and cut time-to-detect.
Build your platform
Corelight Collections ship with your Corelight subscription and activate on demand. Turn individual packages on or off through the Sensor Management or Fleet Manager interface, tuning detection and enrichment coverage to what the environment requires.
Maximize ROI with services and training from Corelight
Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.
-
Accelerate implementation and time to value with health checks
-
Precision engineering for detection calibration and customization
-
Expert-led training and education services
FAQ
How do Corelight Collections improve my detection coverage?
Corelight Collections are a key part of a multi-layered detection architecture across 108+ MITRE ATT&CK tactics, techniques, and procedures (TTPs), including behavioral detections focused on command and control (C2), lateral movement, reconnaissance, and exfiltration. Instead of stitching together one-off rules, you get broad, TTP-based coverage that maps cleanly to the framework your SOC already reports against
Do Collections replace Zeek, Suricata, YARA, threat intelligence, or machine learning?
No, Collections work alongside all of them. They build on Zeek telemetry and run alongside Suricata signatures, YARA file analysis, Corelight Threat Intelligence, and machine learning detections, giving you a single, unified evidence model rather than a pile of disconnected tools.
How do Collections help when EDR can't see the threat?
Collections give you network-level ground truth across unmanaged devices, IoT, and edge systems where endpoint agents can't run or are easily bypassed. That helps close the EDR gap and catch evasive behavior like lateral movement and credential abuse that lives entirely in network traffic.
How does the Entity Collection help with asset visibility and threat hunting?
The Entity Collection automatically tracks and aggregates your network entities, including hosts, devices, services, certificates, users, and domains, into compact logs. You get a living inventory of what's actually on your network, including the unmanaged and forgotten assets attackers love. For threat hunting, these aggregated logs are significantly smaller than raw Zeek logs, so queries run faster and lookbacks stretch further. A shared UID lets you chain entity activity together across time, turning timeline reconstruction into a pivot, not a research project.
How do I deploy and manage Collections across my sensor fleet?
You manage Collections centrally through Fleet Manager, a single console for enabling packages, tuning configurations, deploying custom rules, and pushing policy across every sensor. Toggle a Collection on, adjust its settings, and apply the change fleet-wide, no per-sensor babysitting required. Because Collections build on the Zeek Package Manager, you can also bundle custom packages and deploy them alongside Corelight's curated detections. Fleet Manager keeps tuning, updates, and policy consistent, so your detection logic stays version-controlled and uniform whether you run five sensors or 500.