Smart PCAP
Accelerate investigations with precise packet capture and one-click SIEM retrievals.
Store packets longer, find them faster
Capture only the packets relevant to your investigations while extending lookback windows up to 10x with Smart PCAP. This integrated module within the Corelight Open NDR Platform lets you define precise capture rules based on traffic characteristics.
Forensic-grade evidence with extended lookback windows
Extend retention from days to weeks or months, reducing storage costs without losing critical forensic evidence. With targeted packet capture, define rules based on IP, port, protocol, or specific Zeek® and Suricata® events to store only what matters.
Seamless investigative pivot
Move from Investigator or SIEM platforms like Splunk or Elastic to packet evidence with a single click. Smart PCAP embeds an spcap.url field in Zeek connection logs, linking directly to the associated PCAP file.
Optimize for cost, retention, and performance with your existing infrastructure
Achieve enterprise-scale forensic capture with flexible cloud strategy or on-prem options that align with your specific budget and retention requirements. Smart PCAP supports local disk, iSCSI, and object storage solutions like AWS S3, Azure Blob, and Google Cloud Storage.
Locate PCAP files needed for an investigation
Direct URL in conn.log
Every Zeek connection log includes an spcap.url field that links directly to the associated packet capture; no manual searching required.
Community ID correlation
Pivot from Zeek-parsed connection logs directly into connection packets using the shared Community ID appended to conn.log.
Built-in access controls
Configurable allow/deny lists and mandatory authentication for every download ensure only authorized personnel access sensitive packet data.
Accelerate workflows across core security operations
Preserved packet-level visibility
Smart PCAP preserves targeted packet-level evidence tied directly to Zeek logs, providing the forensic depth defenders need to validate findings and support compliance requirements.
Calibrated threat detection
Capture packets triggered by Suricata alerts or Zeek notices so you can immediately verify whether a signature hit represents a real threat or a false positive.
Confident incident response
When responding to an active incident, you can retrieve the exact packets for any suspicious connection with a single click, accelerating containment and root-cause analysis.
Extend your investigations across the platform
Intrusion Detection
When a Suricata alert fires, Smart PCAP lets analysts instantly retrieve the associated packets for that session, providing full payload context to validate whether a signature hit is a true positive.
File Analysis with YARA
When YARA flags a malicious file extracted from network traffic, Smart PCAP preserves the raw packets for that connection, giving analysts the ability to reconstruct the full file transfer and inspect delivery mechanisms.
Agentic Triage
Agentic Triage uses Smart PCAP download links embedded in Zeek logs to automatically pull relevant packet evidence into AI-driven investigation workflows, accelerating time to resolution.
Build your platform
Smart PCAP is a subscription-based module that can be purchased with Corelight Sensors and enables targeted packet capture in air-gapped, hybrid, cloud, or multicloud environments. You can enable and manage Smart PCAP through the Sensor UI or Fleet Manager.
Maximize ROI with services and training from Corelight
Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.
-
Accelerate implementation and time to value with health checks
-
Precision engineering for detection calibration, and customization
-
Expert-led training and education services
FAQ
What is Corelight Smart PCAP?
Corelight Smart PCAP is a rule-based packet capture system that selectively captures only the network packets relevant to security investigations, rather than storing all traffic. It integrates with Zeek logs and provides direct access to PCAPs via a URL in the connection log, streamlining forensic workflows.
How does Smart PCAP help reduce storage costs?
By capturing only targeted packets based on customizable rules and filters, Smart PCAP dramatically reduces the volume of stored data compared to full packet capture, extending lookback windows from days to weeks or months while lowering storage requirements and costs.
How do analysts retrieve packet captures with Smart PCAP?
Smart PCAP embeds a direct download link (spcap.url) in Zeek connection logs, allowing analysts to retrieve relevant PCAPs with a single click from their SIEM or log management platform, accelerating incident response and investigation.
What storage options does Smart PCAP support?
Smart PCAP supports local disk storage, iSCSI-attached storage arrays, and object storage solutions such as AWS S3, Azure Blob, and Google Cloud Storage, providing flexibility to fit different environments and retention needs.
How does Smart PCAP ensure security and access control?
Smart PCAP enforces access controls through allow/deny lists and requires authentication for PCAP downloads, ensuring that only authorized users can access sensitive packet data.