Skip to content
  • There are no suggestions because the search field is empty.
PROTECTING OVER $1B IN DAILY TRADES
DEFENDING ENERGY FOR 32+M U.S. USERS
SECURING NETWORKS FOR 52K+ TRANSPORT VEHICLES
PROTECTING OVER $10T IN MANAGED ASSETS
SECURING 16+M ANNUAL PATIENT VISITS
Product

Core collection

Curated insights from the Zeek® community plus tools that lower TCO from Corelight.

Detect cryptomining, port scans, and more

The Core Collection provides threat detection for lateral movement, port scanning, cryptomining and more via analytics developed by the Zeek community. It also includes options to enrich the evidence generated by our Open NDR Platform with additional context and can help customers reduce their SIEM costs via platform data controls. Read more on the blog.

Corelight Collections are analytics included with your Corelight subscription and can be activated depending on your needs.

  • Fast investigations with standards like JA3(S) and Community ID
  • Lower SIEM data ingestion and related costs
  • Optimize sensor performance to do more with less
core-collection-detect-section

VPN, DNS, and encryption detection

How it works

Packages in the Core Collection can be enabled or disabled within the Corelight Sensor Management and Fleet Management user interfaces to enhance, enrich, and extend the Open NDR Platform.
core-collection-how-it-works-section