Skip to content
  • There are no suggestions because the search field is empty.
PROTECTING OVER $1B IN DAILY TRADES
DEFENDING ENERGY FOR 32+M U.S. USERS
SECURING NETWORKS FOR 52K+ TRANSPORT VEHICLES
PROTECTING OVER $10T IN MANAGED ASSETS
SECURING 16+M ANNUAL PATIENT VISITS
Platform module

Intrusion Detection System with Suricata®

IDS with signature-based detection analyzes vast traffic volumes to identify network threats.

IDS-frame--icon

Fully integrated Suricata IDS

Real-time signature-based deterministic detections of known attacks paired with Corelight’s industry-leading network evidence.

Unified detection context

Corelight’s Open NDR Platform fuses signature-based IDS alerts from Suricata with Zeek® network evidence, providing a correlated package to your SIEM, XDR, or Investigator. With this deep integration, you accelerate identification, risk assessment, containment, and closure.

Corelight_Graphics_IDSFlow

High-performance defense against known attacks

Get immediate, real-time threat detection of known attacks, backed by precise, actionable analysis that eliminates guesswork. Investigate, validate, and neutralize threats swiftly with the evidence to back every decision.

True Positives graphic

Curated intelligence from experts

Leverage industry-leading signature feeds, Corelight Labs’ own rulesets, and curated community-contributed signatures for faster identification of new threats. AI-enhanced IOCs deliver real-time intelligence tailored to your infrastructure.

binary-monitoring-lines-mision--HeroIllustration

Open-source Zeek is powerful. A platform that operationalizes it is unstoppable.

Integration that's already built

DIY Zeek means stitching Suricata and Zeek together yourself, then maintaining that connection forever. Corelight delivers Suricata alerts and Zeek evidence pre-correlated, so your team can start investigating instead of integrating.

Every alert links to the evidence that proves it

With DIY Zeek, matching a Suricata alert to the right session log is manual detective work. Corelight uses a single UID to link every signature hit directly to its relevant Zeek logs, so context is instant, not assembled.

Curated rules and intel, ready out of the box

Open source means you manage Suricata rules and threat intel feeds on your own. Corelight delivers enterprise-grade rule management, curated intelligence, and AI-enhanced IOCs that are pre-tuned, then ships correlated alerts straight to your SIEM or XDR. No pipeline to build.

Capabilities

Context for evidence, detection, and response capabilities

Defensible network visibility

Every Suricata alert arrives backed by Zeek network evidence, so you can see exactly what happened on the wire. This ground truth turns a noisy alert into a clear, defensible conclusion.

Prioritized, risk-ranked threat detection

Corelight layers signature-based IDS with AI, machine learning, behavioral analytics, and threat intelligence. The result is prioritized, risk-ranked detection that surfaces real threats and quiets the noise.

Contextual incident response

When an alert fires, your team already has the context needed to act. Correlated evidence and a unique ID per entity let analysts investigate, validate, and close cases faster, with SOAR and XDR integrations to help accelerate remediation.

Works best with

Extend your investigations across the platform

Build your platform

IDS with Suricata is a subscription-based offering that comes with Corelight Sensors. Deploy it across air-gapped, hybrid, cloud, and multicloud environments. Enable it in Fleet Manager, and access it on our SaaS solution, Investigator. Your team gets detection and evidence working together from day one.

Corelight_Hero_Platform--Build-your-platform

Maximize ROI with services and training from Corelight

Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.

  • Accelerated implementation and time to value with health checks

  • Precision engineering for detection calibration and customization

  • Expert-led training and education services

training-hero
 

FAQ