Intrusion Detection System with Suricata®
IDS with signature-based detection analyzes vast traffic volumes to identify network threats.
Fully integrated Suricata IDS
Real-time signature-based deterministic detections of known attacks paired with Corelight’s industry-leading network evidence.
Unified detection context
Corelight’s Open NDR Platform fuses signature-based IDS alerts from Suricata with Zeek® network evidence, providing a correlated package to your SIEM, XDR, or Investigator. With this deep integration, you accelerate identification, risk assessment, containment, and closure.
High-performance defense against known attacks
Get immediate, real-time threat detection of known attacks, backed by precise, actionable analysis that eliminates guesswork. Investigate, validate, and neutralize threats swiftly with the evidence to back every decision.
Curated intelligence from experts
Leverage industry-leading signature feeds, Corelight Labs’ own rulesets, and curated community-contributed signatures for faster identification of new threats. AI-enhanced IOCs deliver real-time intelligence tailored to your infrastructure.
Open-source Zeek is powerful. A platform that operationalizes it is unstoppable.
Integration that's already built
DIY Zeek means stitching Suricata and Zeek together yourself, then maintaining that connection forever. Corelight delivers Suricata alerts and Zeek evidence pre-correlated, so your team can start investigating instead of integrating.
Every alert links to the evidence that proves it
With DIY Zeek, matching a Suricata alert to the right session log is manual detective work. Corelight uses a single UID to link every signature hit directly to its relevant Zeek logs, so context is instant, not assembled.
Curated rules and intel, ready out of the box
Open source means you manage Suricata rules and threat intel feeds on your own. Corelight delivers enterprise-grade rule management, curated intelligence, and AI-enhanced IOCs that are pre-tuned, then ships correlated alerts straight to your SIEM or XDR. No pipeline to build.
Context for evidence, detection, and response capabilities
Defensible network visibility
Every Suricata alert arrives backed by Zeek network evidence, so you can see exactly what happened on the wire. This ground truth turns a noisy alert into a clear, defensible conclusion.
Prioritized, risk-ranked threat detection
Corelight layers signature-based IDS with AI, machine learning, behavioral analytics, and threat intelligence. The result is prioritized, risk-ranked detection that surfaces real threats and quiets the noise.
Contextual incident response
When an alert fires, your team already has the context needed to act. Correlated evidence and a unique ID per entity let analysts investigate, validate, and close cases faster, with SOAR and XDR integrations to help accelerate remediation.
Extend your investigations across the platform
Network Security Monitoring with Zeek
Suricata alerts are linked directly to the Zeek session logs that captured the same traffic, giving every signature hit immediate evidence and forensic context.
Smart PCAP
Corelight Smart PCAP links Zeek logs, detections, and extracted files to only the packets you need for investigations. Store packets longer; find them faster.
Threat Intelligence
Curated, high-confidence IOCs, powered by CrowdStrike, are updated hourly to enable rapid identification of known and unknown threats.
Build your platform
IDS with Suricata is a subscription-based offering that comes with Corelight Sensors. Deploy it across air-gapped, hybrid, cloud, and multicloud environments. Enable it in Fleet Manager, and access it on our SaaS solution, Investigator. Your team gets detection and evidence working together from day one.
Maximize ROI with services and training from Corelight
Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.
-
Accelerated implementation and time to value with health checks
-
Precision engineering for detection calibration and customization
-
Expert-led training and education services
FAQ
What is an intrusion detection system (IDS)?
An intrusion detection system (IDS) is an alert-based system that monitors and analyzes network traffic for evidence of malicious or unauthorized activity. When it detects malicious behavior, such as attempts to access restricted areas or exploit vulnerabilities in an endpoint or application, security teams receive a notification that can lead to direct response or further investigation. An IDS cannot remediate a security event on its own. Historically, intrusion detection systems have worked alongside intrusion prevention systems (IPS), which can actively block traffic or network packets, modify access control, or undertake other mitigation tactics.
How do you reduce IDS false positives?
Security teams reduce IDS false positives by regularly tuning, streamlining, and updating IDS rules and features, and by verifying alerts with network evidence so analysts can validate them quickly. The most serious risk from false positives arises when security teams become overwhelmed and can no longer distinguish between likely harmless alerts and those that demand investigation, whether they signal malicious activity or misconfigurations that hurt network performance. An excess of false positives shows that a security team's resources are stretched thin and that the organization's overall security posture is not where it should be. Taking these actions streamlines alerting systems and makes IDS and other security tools more efficient.
What's the difference between IDS and IPS?
Intrusion detection systems (IDS) and intrusion prevention systems (IPS) are cybersecurity tools that alert security teams to possible intrusions in company systems. People sometimes refer to intrusion prevention and detection as two parts of a single system (IDPS). Historically, however, many organizations have deployed one or the other, or treated IDS and IPS as separate but mutually reinforcing functions. An IDS cannot remediate a security event on its own.
NDR vs. IDS: Which is best for threat detection?
While traditional IDS uses signature-based detection, some solutions have integrated anomaly and machine learning detections. Network Detection and Response (NDR), like network IDS, monitors network traffic, but it scans far more complex environments, including cloud, hybrid, and multi-cloud infrastructure, network firewalls, SaaS, traffic from remote users, network taps, and servers. NDR lets security teams monitor lateral movement, making it far more likely to catch malicious actors who slipped past perimeter defenses by compromising remote accounts or devices. Most security teams need both for a best-in-class solution. Organizations can use NDR to pre-correlate core IDS detection capabilities, accelerating investigation and response across all SecOps teams.
How does Corelight improve traditional IDS?
Traditional IDS hands you an alert and leaves you to find the rest. Corelight pairs signature-based Suricata alerts with Zeek network evidence, then delivers that correlated package to your SIEM, XDR, or Investigator. Investigator’s Agentic Triage can also correlate Suricata alerts with detections from other Corelight detection layers, adding confidence to every alert. Each package carries a unique ID per entity, so analysts can find related data fast with basic queries. The outcome is faster triage, sharper investigation, and fewer alerts left unexplained, all within a single Open NDR Platform.