Investigator
Evidence-first triage powered by AI/ML detections and explainable agentic AI. Replace noisy, isolated alerts with clear, entity-centric case files and transparent reasoning.
Leverage the power of agentic AI
Investigator is Corelight’s SaaS-based NDR platform that streamlines complex investigations by eliminating repetitive review steps, enabling up to 10x faster triage and more informed decision-making. Move from alert to validated decision in minutes with durable network telemetry, deep packet intelligence, and AI-driven playbooks.
Trust: Transparent, defensible reasoning
Transparent playbooks and visible reasoning allow teams to trust AI assistance while retaining full control over decisions and outcomes.
Speed: GenAI attacks require GenAI defense
Keep pace with AI-driven attacks through automated, structured investigations that scale beyond human-only workflows. Investigator maps every detection to MITRE ATT&CK techniques to deliver evidence-backed next-step recommendations that help stop lateral movement and data exfiltration.
Efficiency: Automate repetitive and time-consuming tasks
Operationalize AI-enabled SOC workflows with clear governance and expert-guided design, modernizing operations safely and without disrupting existing processes.
Gartner® and Peer Insights™ are trademarks of Gartner, Inc. and/or its affiliates. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose
Optimized Real-Time Visibility and AI/ML Capabilities with Corelight
The best part of the product is leveraging their full suite of capabilities, not just their sensor, but what they bring in real time visibility and AI/ML with their Investigator product.
CEO, Government
How it works
Reduce triage time with autonomous triage
Corelight Investigator reduces investigation time by automating triage that consolidates and analyzes the highest-priority entities in your environment every 24 hours:
- Agentic Triage uses transparent, expert-written playbooks to follow consistent, defensible triage logic for every investigation
- Automatically investigates the last seven days of host activity to identify persistent patterns, lateral movement, and long-term TTPs
- Performs advanced detection correlation and analyzes dozens of raw log queries to unify disparate data points into a single narrative
- Provides analysts with a ready-to-use narrative, reasoning, and recommended next steps, eliminating the need for manual data stitching
Expand detection, validation, and coverage
Investigator enhances detection impact by validating alerts through structured investigative workflows:
- Transparent AI/ML models
- Behavioral, signature, threat intel, and query-based detections
- MITRE ATT&CK® coverage across 100+ techniques
- Deep visibility into Defense Evasion, Credential Access, Discovery, and C2
Increase SOC efficiency with entity-centric investigation
Investigator empowers analysts to make informed decisions quickly by capturing all relevant data within a structured investigation framework. Automated playbooks, explainable AI summaries, and triage history reduce skill gaps and enable junior analysts to perform at senior levels:
- 3x more cases handled per analyst
- Toolset and dataset consolidation
- Single-screen, entity-based triage experience
- Out-of-the-box and customizable dashboards
- Easy access to raw data and GenAI summaries
Enhanced response capabilities with built-in containment
Investigator allows analysts to move from verified investigation to response within the same interface. With a single click, analysts can isolate compromised hosts, enforce firewall policy changes, and trigger response actions directly from validated cases:
- Detection-to-response within one workflow
- One-click host isolation and containment
- Streamlined workflows that reduce response times
- Evidence-backed justification for every action taken
Global retailer hunts threats, halts PoS breach
Situation
A global beauty retailer needed deeper network visibility to protect thousands of point-of-sale (PoS) terminals and proactively hunt for threats across its corporate environment.
Challenge
Identifying a single compromised device among thousands is difficult, especially when threats range from hidden C2 channels to malicious .onion traffic designed to exfiltrate card data.
Solution
Corelight Investigator flagged a DNS query to a malicious .onion domain from a PoS terminal. Corelight’s evidence also revealed previously unseen threats on the corporate network, including C2 beaconing and unauthorized bitcoin mining.
Results
The team immediately isolated the compromised PoS terminal, averting a data breach. They also used the evidence to re-image several other compromised workstations, validating their threat hunting program.
Maximize ROI with services and training from Corelight
Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.
- Accelerate implementation and time to value with health checks
- Precision engineering for detection calibration and customization
- Expert-led training and education services
FAQ
How does Investigator accelerate incident response?
Investigator connects alerts to structured network evidence and produces clear summaries that explain what happened and what to do next. Analysts can pivot into deeper investigations or packet-level forensics without switching tools.
How does Investigator fit into my existing SOC stack?
Investigator integrates with major SIEM, XDR, and SOAR platforms. It enriches alerts, exports evidence to downstream tools, and provides an investigation hub that strengthens the performance of your existing security investments.
What types of data does Investigator analyze?
Investigator ingests structured network evidence, logs, and metadata created by Corelight Sensors. This includes behavioral insights, protocol-level details, threat detections from Suricata, and Smart PCAP for deep validation.
Who benefits from Investigator?
Tier 1 analysts gain clear summaries and faster triage. Tier 2 analysts use guided workflows to identify root cause. Tier 3 analysts and threat hunters rely on deep evidence, queries, and forensic access. Any SOC facing visibility or triage challenges benefits immediately.
How is Investigator deployed?
Investigator is delivered as a SaaS platform and ingests evidence from Corelight Sensors deployed across physical, virtual, and cloud environments, including AWS, Azure, and GCP.