Skip to content
  • There are no suggestions because the search field is empty.
PROTECTING OVER $1B IN DAILY TRADES
DEFENDING ENERGY FOR 32+M U.S. USERS
SECURING NETWORKS FOR 52K+ TRANSPORT VEHICLES
PROTECTING OVER $10T IN MANAGED ASSETS
SECURING 16+M ANNUAL PATIENT VISITS
Platform module

Network Security Monitoring with Zeek®

Transform raw network traffic into forensic-grade evidence with the world's most trusted network analysis engine. Powered by Zeek, (deployed in over 10,000 environments worldwide) Corelight delivers the context, behavioral intelligence, and extensibility defenders need to stay ahead of threats.

Zeek_HeroIllustration

From raw traffic to forensic-grade network evidence

Go beyond basic alerts with network security monitoring that delivers deep context, real-time behavioral analysis, and modular extensibility. Powered by Zeek, Corelight turns every packet into actionable intelligence for your security operations.

Forensic-grade context for every investigation

Corelight transforms raw network traffic into a context-rich, protocol-detailed history across HTTP, DNS, SSL/TLS, and dozens of other protocols. By capturing high-fidelity metadata and Smart PCAP, it empowers analysts to reconstruct events and trace attacker actions with absolute precision, on-prem or in the cloud.

cyber-monitoring-code

Event-driven behavioral logic that catches what signatures miss

Go beyond static rules. Corelight enables real-time behavioral analysis, protocol decoding, and stateful connection tracking to detect suspicious network activity like lateral movement, data exfiltration, and protocol misuse. By analyzing deviations from predefined thresholds, it uncovers novel attacks and provides the early warning needed for proactive defense.

Corelight_ZeekPhishing-1

Modular extensibility to match your environment

Leverage Zeek's modular frameworks (Signature, Intel, Notice, and File Analysis) to tailor network monitoring to your environment and accelerate SOC maturity. Write or modify scripts, add new protocol analyzers, and seamlessly enrich logs with external threat intelligence to meet the unique demands of your operations.

enrichment-data--graphic

Scalable, efficient evidence collection

Corelight produces compact, standardized logs that are easy to store, search, and integrate with Investigator, SIEM, SOAR, and XDR platforms. Optimized for high-throughput environments and built for enterprise scale, it ensures the long-term retention of high-fidelity network evidence so you never miss a critical detail.

Corelight_Graphics_ZeekEvidenceCollection

Corelight vs. open-source Zeek

Forensic-grade context at scale

Corelight integrates Smart PCAP with Zeek's rich metadata, letting analysts pivot instantly from a log entry to the exact underlying packets for forensic validation, without the massive storage overhead of traditional full-packet capture. Combined with identity enrichment and asset classification, every log tells the full story.

Behavioral detection & ML

Corelight extends Zeek with a multi-layered machine learning engine for detecting behavioral anomalies that rule-based systems miss. ML models (from random forests to deep learning) run at the edge and in the cloud, specifically targeting "low and slow" threats like DNS tunneling, domain generation algorithms (DGAs), and lateral movement patterns.

Enterprise management & log optimization

Corelight merges Zeek with enterprise features including an intuitive management UI, sensor health metrics, fleet management, and automated data export to Splunk, Elastic, Kafka, Syslog, and S3. Integrated log reduction typically cuts data volume by 30-50% without losing critical security metadata.

Capabilities

Operationalizing intelligence across your workflow

Ground-truth network evidence for complete visibility

Generates the 70+ protocol-rich log types that form Corelight's high-fidelity evidence layer across every environment.

Multi-layered threat detection

Provides the network telemetry that feeds every detection engine, including ML models, behavioral analytics, and curated signature-based alerts.

Agentic incident response

Delivers UID-linked session logs, DNS records, and file artifacts for forensic pivots during active investigations.

Works best with

Actionable intelligence for agentic triage and forensics

Build your platform

Network Security Monitoring is a required annual subscription sold with Corelight Sensors. It can be deployed across air-gapped, hybrid, cloud, and multicloud environments. The sensors generate detailed logs for incident response and tool integration to deliver actionable network evidence.

Corelight_Hero_Platform--Build-your-platform

Maximize ROI with services and training from Corelight

Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.

  • Accelerate implementation and time to value with health checks
  • Precision engineering for detection calibration, and customization
  • Expert-led training and education services
training-hero
 
 

FAQ