Skip to content
  • There are no suggestions because the search field is empty.
PROTECTING OVER $1B IN DAILY TRADES
DEFENDING ENERGY FOR 32+M U.S. USERS
SECURING NETWORKS FOR 52K+ TRANSPORT VEHICLES
PROTECTING OVER $10T IN MANAGED ASSETS
SECURING 16+M ANNUAL PATIENT VISITS
Platform module

Smart PCAP

Accelerate investigations with precise packet capture and one-click SIEM retrievals.

Store packets longer, find them faster

Capture only the packets relevant to your investigations while extending lookback windows up to 10x with Smart PCAP. This integrated module within the Corelight Open NDR Platform lets you define precise capture rules based on traffic characteristics.

Forensic-grade evidence with extended lookback windows

Extend retention from days to weeks or months, reducing storage costs without losing critical forensic evidence. With targeted packet capture, define rules based on IP, port, protocol, or specific Zeek® and Suricata® events to store only what matters.

Smart PCAP - Graphic

Seamless investigative pivot

Move from Investigator or SIEM platforms like Splunk or Elastic to packet evidence with a single click. Smart PCAP embeds an spcap.url field in Zeek connection logs, linking directly to the associated PCAP file.

Connection log and PCAP data visualization diagram

Optimize for cost, retention, and performance with your existing infrastructure

Achieve enterprise-scale forensic capture with flexible cloud strategy or on-prem options that align with your specific budget and retention requirements. Smart PCAP supports local disk, iSCSI, and object storage solutions like AWS S3, Azure Blob, and Google Cloud Storage.

Smart PCAP - Graphic 3 - V2a-3

Locate PCAP files needed for an investigation

Direct URL in conn.log

Every Zeek connection log includes an spcap.url field that links directly to the associated packet capture; no manual searching required.

Community ID correlation

Pivot from Zeek-parsed connection logs directly into connection packets using the shared Community ID appended to conn.log.

Built-in access controls

Configurable allow/deny lists and mandatory authentication for every download ensure only authorized personnel access sensitive packet data.

Capabilities

Accelerate workflows across core security operations

Preserved packet-level visibility

Smart PCAP preserves targeted packet-level evidence tied directly to Zeek logs, providing the forensic depth defenders need to validate findings and support compliance requirements.

Calibrated threat detection

Capture packets triggered by Suricata alerts or Zeek notices so you can immediately verify whether a signature hit represents a real threat or a false positive.

Confident incident response

When responding to an active incident, you can retrieve the exact packets for any suspicious connection with a single click, accelerating containment and root-cause analysis.

Works best with

Extend your investigations across the platform

Build your platform

Smart PCAP is a subscription-based module that can be purchased with Corelight Sensors and enables targeted packet capture in air-gapped, hybrid, cloud, or multicloud environments. You can enable and manage Smart PCAP through the Sensor UI or Fleet Manager.

Corelight_Hero_Platform--Build-your-platform

Maximize ROI with services and training from Corelight

Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.

  • Accelerate implementation and time to value with health checks

  • Precision engineering for detection calibration, and customization

  • Expert-led training and education services

training-hero
 
 

FAQ