CONTACT US
forrester wave report 2023

Close your ransomware case with Open NDR

SEE HOW

ad-nav-crowdstrike

Corelight now powers CrowdStrike solutions and services

READ MORE

ad-images-nav_0013_IDS

Alerts, meet evidence.

LEARN MORE ABOUT OUR IDS SOLUTION

ad-images-nav_white-paper

5 Ways Corelight Data Helps Investigators Win

READ WHITE PAPER

glossary-icon

10 Considerations for Implementing an XDR Strategy

READ NOW

ad-images-nav_0006_Blog

Don't trust. Verify with evidence

READ BLOG

video

The Power of Open-Source Tools for Network Detection and Response

WATCH THE WEBCAST

ad-nav-ESG

The Evolving Role of NDR

DOWNLOAD THE REPORT

ad-images-nav_0006_Blog

Detecting 5 Current APTs without heavy lifting

READ BLOG

g2-medal-best-support-spring-2024

Network Detection and Response

SUPPORT OVERVIEW

 

ALL PRODUCTS

See all of the products that power our Open NDR Platform, from our sensors to open-source and proprietary evidence collections to our analytics and SaaS solutions.

products-web

OPEN NDR PLATFORM

 

computer-investigator-product

 

Investigator

The only evidence-first threat investigation platform. Investigator is a SaaS-based network detection and response solution that dramatically simplifies Tier 1 workflows, accelerating triage and resolution.

LEARN MORE

zeek logo

 

Zeek

The standard for network traffic monitoring and proactive data-first defense, Zeek® is foundational to the Open NDR Platform. 

LEARN MORE

alert-green-1

 

IDS

The best-in-class open source alerting engine—Suricata IDS—deeply integrated into the Open NDR Platform. 

LEARN MORE

smart-pcap-logo

 

Smart PCAP

Capture just the packets you need for investigations, and store months—not minutes—of traffic history.

LEARN MORE


 

COLLECTIONS

Security analytics developed by Corelight Labs, along with curated additions from the Zeek community.

 

300-collections-icons-cmyk_ig-collections-c2-collection-cmyk

 

C2 Collection

50+ detections and insights into known command and control activity, as well as MITRE ATT&CK® C2 techniques for finding novel attacks.

LEARN MORE

large-ig-collections-core-collection-rgb

 

Core Collection

Proprietary packages that help sensors scale in high-throughput environments, combined with curated insights from the Zeek community.

LEARN MORE

300-collections-icons-cmyk_ig-collections-encrypted-collection-cmyk

 

Encrypted Traffic Collection

Dozens of insights into SSL, SSH, and RDP connections enhanced with community contributions like JA3—all without decryption.

LEARN MORE

large-ig-collections-entities-collection-rgb

 

Entity Collection

Allows easy searching and grouping on entity inventory, including identification of subnets and 80+ applications.

LEARN MORE

corelight-collections-ics

 

ICS/OT Collection

Identify and log ICS/OT protocols like BACnet, DNP3, Ethercat, Modbus, and more.

LEARN MORE


 

 

APPLIANCE SENSORS

Hardware sensors with enterprise-grade stability and performance. Deployment takes just minutes.

 

 

AP 200

 

AP 200 Series Appliance Sensors

Throughput: 2 Gbps | Support for copper and/or optical modules at 100M and 1G

LEARN MORE

AP 1000

 

AP 1000 Series Appliance Sensors

Throughput: 10-20 Gbps  |  Support for copper and/or optical modules at 1G and/or 10G

LEARN MORE

AP 3000

 

AP 3000 Series Appliance Sensors

Throughput: 20-35 Gbps |  Support for copper and/or optical modules at 1G and 10G or 40G

LEARN MORE

AP 5000

 

AP 5000 Series Appliance Sensors

Throughput: 100+ Gbps | Support for optical modules at 8 x 10G, 2 x 40G or 2 x 100G

LEARN MORE


 

CLOUD SENSORS

Corelight’s cloud security solutions allow you to detect and respond to threats that target cloud workloads.

 

cloud-sensor-for-aws

 

Cloud Sensors

Deploy in AWS, GCP, and Azure environments. SaaS and self-managed options available.

LEARN MORE


 

SOFTWARE SENSOR

Easily deploy Corelight on any Linux platform, or within containers, via a lightweight software binary.

 

Corelight-Software-icon-Small

 

Software Sensor

Throughput: 8 Gbps

LEARN MORE


 

VIRTUAL SENSORS

Corelight's Hyper-V and VMware NDR virtual sensors transform network traffic into high-fidelity data for incident response, intrusion detection, and more.

 

cloud-sensor-for-aws-1

 

Virtual Sensors

Available for Hyper-V and VMware | Throughput: up to 8 Gbps

LEARN MORE


 

fleet-manager-product

 

Fleet Manager

Corelight Fleet Manager gives you the ability to manage your entire fleet of sensors from one user-friendly GUI console. Create custom configuration templates in minutes to manage individual sensors, groups, or your entire fleet.

LEARN MORE

Have questions?

Talk with one of our experts today.

CONTACT US