Performance and Asset Visibility
Open NDR Sensors passively classify every network asset and surface threshold-based performance alerts from traffic you're already collecting, giving security and network operations teams a shared source of truth from a single deployment.
One sensor. Complete visibility for security and network operations.
Performance and Asset Visibility is a Corelight Open NDR module that passively extracts asset classification and network performance telemetry from traffic your sensors are already collecting. No additional hardware, agents, or dedicated NetOps tools required.
Visibility into actively exploited devices
Open NDR Sensors passively discover and classify every device by analyzing protocol fingerprints to identify device type, OS, manufacturer, and network role. When a threat is detected, asset context such as device type, OS, and network role appears in the same log entry as the alert.
Prove "it's not the network" in minutes, not hours
Open NDR generates domain-aware alerts correlated to actual service names: DNS query names, TLS, QUIC traffic, SNI, and HTTP Host headers. The anomaly-first architecture fires only when configurable thresholds are crossed, instantly answering in a single log entry which side of the sensor is the problem. Every performance alert includes a direct forensic pivot to the exact connection that triggered the threshold.
One sensor, one truth for SecOps and NetOps
Extract high-fidelity, anomaly-first performance signals from traffic already flowing through your Open NDR Sensors. No additional hardware, no active polling agents, no dedicated NetOps vendor bloat. Both teams work from the same evidence layer without tool-switching. Your Open NDR platform investment delivers value to both security and network operations from a single deployment.
Operationalizing intelligence across your workflow
Network visibility
Enrich log entries with device identity and performance context with asset_classification.log and net_perf.log integrated directly with the Open NDR evidence layer. Both logs share the same UIDs that link every Open NDR log type, making asset and performance data natively queryable in your SIEM.
Threat detection
Asset classification enables detection prioritization by device criticality and role. An alert on a domain controller triggers a different response than one on a guest Wi-Fi laptop. That context comes from asset_classification.log, without a CMDB query or manual lookup.
Incident response
During an investigation, asset classification identifies exactly what you're investigating: device type, OS, manufacturer, and network role, enriched directly into the alert. For incidents involving unmanaged and IoT devices, network-derived asset identity is the only available source of information.
Unlock deeper insights for maximum value
Network Security Monitoring with Zeek
Suricata alerts are linked directly to the Zeek session logs that captured the same traffic, giving every signature hit immediate evidence and forensic context.
Agentic Triage
Agentic Triage reads Zeek protocol logs as the ground truth for every AI-authored investigation step and playbook finding.
Threat Intelligence
Curated, high-confidence IOCs, powered by CrowdStrike, are updated hourly to enable rapid identification of known and unknown threats.
Build your platform
Performance and asset visibility is included in both the Open NDR Sensor and Investigator bundles at no additional cost. Asset classification is available as an add-on SKU.
Maximize ROI with services and training from Corelight
Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.
- Accelerate implementation and time to value with health checks
- Precision engineering for detection calibration, and customization
- Expert-led training and education services
FAQ
What is the Performance and Asset Visibility module, and what does it do?
Performance and Asset Visibility is a Corelight Open NDR module that extracts two operational intelligence streams from your existing sensors: passive asset classification via asset_classification.log and network performance telemetry via net_perf.log. No additional hardware, active polling agents, or dedicated NetOps tools required. Both capabilities run from traffic you're already collecting.
How does network performance monitoring work, and why does it only alert when something is wrong?
Net-perf uses an anomaly-first architecture. It aggregates session-level TCP RTT measurements across a configurable time window and generates a net_perf.log entry only when a threshold is crossed, not as a continuous telemetry stream. VantageTime, a Open NDR-sensor-only capability, delivers placement-aware decomposition of latency into client-side (cli_rtt) and server-side (svr_rtt). Every alert includes the UID of the first connection that triggered it, so analysts pivot directly to the exact conn.log entry for investigation.
How does asset classification work?
Open NDR passively fingerprints devices by analyzing protocol signatures captured in traffic. Every asset is classified by device type, OS, manufacturer, model, and network role. Classification happens continuously as traffic is observed, covering unmanaged endpoints, IoT, and shadow IT that bypass traditional inventory tools.