Network Security Monitoring with Zeek®
Transform raw network traffic into forensic-grade evidence with the world's most trusted network analysis engine. Powered by Zeek, (deployed in over 10,000 environments worldwide) Corelight delivers the context, behavioral intelligence, and extensibility defenders need to stay ahead of threats.
From raw traffic to forensic-grade network evidence
Go beyond basic alerts with network security monitoring that delivers deep context, real-time behavioral analysis, and modular extensibility. Powered by Zeek, Corelight turns every packet into actionable intelligence for your security operations.
Forensic-grade context for every investigation
Corelight transforms raw network traffic into a context-rich, protocol-detailed history across HTTP, DNS, SSL/TLS, and dozens of other protocols. By capturing high-fidelity metadata and Smart PCAP, it empowers analysts to reconstruct events and trace attacker actions with absolute precision, on-prem or in the cloud.
Event-driven behavioral logic that catches what signatures miss
Go beyond static rules. Corelight enables real-time behavioral analysis, protocol decoding, and stateful connection tracking to detect suspicious network activity like lateral movement, data exfiltration, and protocol misuse. By analyzing deviations from predefined thresholds, it uncovers novel attacks and provides the early warning needed for proactive defense.
Modular extensibility to match your environment
Leverage Zeek's modular frameworks (Signature, Intel, Notice, and File Analysis) to tailor network monitoring to your environment and accelerate SOC maturity. Write or modify scripts, add new protocol analyzers, and seamlessly enrich logs with external threat intelligence to meet the unique demands of your operations.
Scalable, efficient evidence collection
Corelight produces compact, standardized logs that are easy to store, search, and integrate with Investigator, SIEM, SOAR, and XDR platforms. Optimized for high-throughput environments and built for enterprise scale, it ensures the long-term retention of high-fidelity network evidence so you never miss a critical detail.
Forensic-grade context at scale
Corelight integrates Smart PCAP with Zeek's rich metadata, letting analysts pivot instantly from a log entry to the exact underlying packets for forensic validation, without the massive storage overhead of traditional full-packet capture. Combined with identity enrichment and asset classification, every log tells the full story.
Behavioral detection & ML
Corelight extends Zeek with a multi-layered machine learning engine for detecting behavioral anomalies that rule-based systems miss. ML models (from random forests to deep learning) run at the edge and in the cloud, specifically targeting "low and slow" threats like DNS tunneling, domain generation algorithms (DGAs), and lateral movement patterns.
Enterprise management & log optimization
Corelight merges Zeek with enterprise features including an intuitive management UI, sensor health metrics, fleet management, and automated data export to Splunk, Elastic, Kafka, Syslog, and S3. Integrated log reduction typically cuts data volume by 30-50% without losing critical security metadata.
Operationalizing intelligence across your workflow
Ground-truth network evidence for complete visibility
Generates the 70+ protocol-rich log types that form Corelight's high-fidelity evidence layer across every environment.
Multi-layered threat detection
Provides the network telemetry that feeds every detection engine, including ML models, behavioral analytics, and curated signature-based alerts.
Agentic incident response
Delivers UID-linked session logs, DNS records, and file artifacts for forensic pivots during active investigations.
Actionable intelligence for agentic triage and forensics
Intrusion Detection
Suricata® alerts are linked directly to the Zeek session logs that captured the same traffic, giving every signature hit immediate forensic context.
Smart PCAP
Corelight Smart PCAP uses conn.log UIDs to retrieve targeted full-packet captures on demand from any Zeek connection record.
Agentic Triage
Agentic Triage reads Zeek protocol logs as the ground truth for every AI-authored investigation step and playbook finding.
Build your platform
Network Security Monitoring is a required annual subscription sold with Corelight Sensors. It can be deployed across air-gapped, hybrid, cloud, and multicloud environments. The sensors generate detailed logs for incident response and tool integration to deliver actionable network evidence.
Maximize ROI with services and training from Corelight
Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.
- Accelerate implementation and time to value with health checks
- Precision engineering for detection calibration, and customization
- Expert-led training and education services
FAQ
What is Zeek and what does it do?
Zeek is an open-source network security monitoring framework that analyzes network traffic at the application layer, extracting rich metadata and generating detailed logs for dozens of protocols. It provides deep visibility into network activity, supporting threat detection, incident response, and forensic investigations.
How does Zeek help with threat detection?
Zeek enables both signature-based and behavioral detection by allowing users to write custom scripts that identify suspicious patterns, anomalies, or protocol misuse. This flexibility helps detect advanced threats that may evade traditional security tools
What types of logs does Zeek generate?
Zeek produces standardized logs for a wide range of protocols and activities, including connection logs (conn.log), DNS queries (dns.log), HTTP transactions (http.log), SSL/TLS sessions (ssl.log), and file transfers (files.log), among others.
Can Zeek be customized for specific environments?
Yes, Zeek is highly extensible. Users can write or modify scripts to add new protocol analyzers, enrich logs, or integrate threat intelligence feeds, tailoring Zeek to their unique security needs and benefiting from a vibrant open-source community.
How does Zeek integrate with Corelight sensors?
Corelight Sensors use Zeek as their core analysis engine, passively monitoring network traffic and leveraging Zeek to generate actionable, high-fidelity logs. These logs are then exported for use in Investigator, SIEM, SOAR, and XDR platforms, supporting comprehensive security operations.