Skip to content
  • There are no suggestions because the search field is empty.
PROTECTING OVER $1B IN DAILY TRADES
DEFENDING ENERGY FOR 32+M U.S. USERS
SECURING NETWORKS FOR 52K+ TRANSPORT VEHICLES
PROTECTING OVER $10T IN MANAGED ASSETS
SECURING 16+M ANNUAL PATIENT VISITS
Platform module

Corelight Collections

Uncover additional insights with Corelight expert-curated detection and enrichment packages.

Curated scripts for detection and visibility

Illuminate evasive and advanced threats with six targeted Collections offering out-of-the-box insights and detections in network protocols, encrypted traffic, entities, and ICS/OT. These collections help detect C2, lateral movement, port scanning, cryptomining, tunneling, domain generation algorithms (DGA), and more. Built on Zeek®, each Collection evaluates how traffic actually behaves, then feeds its findings into Corelight's evidence and analytics layer.

Empower your team with purpose-built detections curated by Corelight

Every Collection targets a specific security problem, from command and control to industrial protocols. Each detection arrives linked to the network evidence that produced it, so analysts begin an investigation with the underlying logs, files, and session context already in hand.

Corelight_Graphic_Teamwork_3

Corelight Collections

Core Collection

core-collection-trans-gradient--icon

Curated insights from the Zeek® community, plus tools that lower total cost of ownership from Corelight. Detect cryptomining, port scans, lateral movement, and more with analytics built on Zeek community contributions and optimized by Corelight. The Core Collection also layers additional context into Open NDR Platform evidence and applies data controls that trim SIEM ingestion volume and cost.

  • Accelerate investigations with standards like JA3(S) and Community ID

  • Lower SIEM data ingestion and related costs

  • Optimize sensor performance to do more with less

Command and Control (C2) Collection

C2-collection-trans-gradient--icon

Discover if an attacker is remotely controlling assets on your network. Find DGA, DNS, and ICMP tunneling. Corelight’s C2 Collection has over 50 unique insights and detections that illuminate command and control activity. Battle-tested by some of the world’s most sophisticated organizations, this collection covers known C2 toolkits and MITRE ATT&CK® C2 techniques to find novel attacks.

  • Catch attacker tunnels camouflaged as normal traffic

  • Find Cobalt Strike, Empire, Metasploit, and other common tools

  • Extend MITRE ATT&CK coverage with 50+ unique C2 detections and insights

Encrypted Traffic Collection

encrypted-traffic-collection-trans-gradient--icon

See and counter threats, even those hidden by encryption, without decryption. Getting visibility into encrypted traffic can seem impossible, but ignoring it gives attackers an ideal hiding place. The Encrypted Traffic Collection turns network data flows into rich evidence and actionable insights, without decryption, so you can understand and mitigate risk. By combining observable elements, like timestamps and packet sizes, with known behavior of protocols, the collection offers a practical approach to visibility that helps you see and act on what matters. It also avoids the heavy financial, privacy, and performance costs of decryption.

  • Find advanced attacks hiding in encrypted traffic

  • Gain visibility into SSL, SSH, RDP, DNS, and VPN traffic

  • Highlight misconfigurations that expose data

Entity Collection

entity-collection-trans-gradient--icon

Network asset discovery and inventory. Track everything connected to your network and build a strong foundation for discovery, profiling, and inventory. Asset inventory management is notoriously difficult in large enterprise environments, where an ever-changing inventory of unknown, unmanaged entities traverses the network. The Corelight Entity Collection gives security teams powerful identification capabilities for applications, devices, services, certificates, hosts, and more, helping them map and defend their environment more comprehensively. The Entity Collection also delivers visibility into specific entity activity, for example, revealing all hosts that have used SSH in the past 24 hours. This capability helps your team determine whether high-value assets have been compromised by insider threats or adversaries leveraging stolen SSH credentials.

  • Identify known apps and new local subnets

  • Discover activity related to hosts, devices, services, names, certs, domains, and users

  • See current entity activity and track it over time

ICS/OT Collection

ICS-OT-collection-trans-gradient--icon

Enhanced visibility and security for ICS/OT devices and protocols. Lack of visibility can create security blind spots in any environment, from a factory floor to an enterprise IT network. Corelight offers a visibility solution for identifying and monitoring the most common Industrial Control System (ICS) and Operational Technology (OT) protocols, improving defense across diverse environments. Use the ICS/OT Collection to identify devices and capture evidence related to ICS/OT protocols, yielding greater visibility and faster incident response times. Monitor uncommon network behavior, such as an HVAC system interacting with a server, and react more quickly to risks by identifying anomalies in enterprise and operational network traffic in real time.

  • Identify and log ICS/OT protocols like BACnet, DNP3, EtherCAT, Modbus, and more

  • Discover activity related to HVAC, security cameras, smart lighting, and access control systems

  • Built on contributions from the Cybersecurity and Infrastructure Security Agency (CISA) 

Analyzers Collection

Analyzer Collection logo

Enhanced visibility into additional specific network protocols. The Analyzers Collection includes expanded visibility into over ten fundamental network protocols. This collection helps to remove security blind spots in the network. Corelight enables security teams to identify and monitor core and common network protocols to enable defense against threats hiding in this traffic. These protocols facilitate secure communication, device discovery, remote access, logging, messaging, and resource sharing across networks, found in specific use cases like VPNs (OpenVPN, WireGuard, IPsec), directory services (LDAP), file sharing (SMB), or event notifications (SSDP, GENA). With the Analyzers Collection, teams can identify protocol-based network traffic anomalies in real time and respond to risks more quickly.

  • Identify and log network protocols, including LDAP, IPsec, SMB, and more

  • Discover activity related to lateral movement in administrative, security, and file-sharing traffic

  • Confirm that only authorized devices and users are utilizing specific protocols, reducing the risk of unauthorized access to sensitive resources like LDAP directories or SMB shares

Capabilities

Get detections and enrichments from the data you already have

Correlated network evidence

Each collection transforms raw traffic into structured, actionable intelligence, delivering high-fidelity detections and rich enrichment grounded in forensic-grade network evidence you can trust. The result is sharper detections, deeper context, and faster investigations.

Elevate AI/ML threat detection

Expand your detection coverage from day one with added command and control (C2) detections and MITRE ATT&CK TTP coverage. Corelight Collections work together with signatures, IOCs, YARA, and machine learning directly on-sensor to deliver multi-layered, high-fidelity detections. The payoff: Smarter data, higher confidence detections, and faster response.

Sharper incident response

When an incident breaks, Corelight Collections enrich your data and tie every detection directly to the network evidence behind it. Analysts can pivot from alert to full context in seconds, not hours, cutting response times by up to 95%. The result is sharper investigations and cases you can close with confidence.

Works best with

Enrich your entire multi-layered detection architecture

Build your platform

Corelight Collections ship with your Corelight subscription and activate on demand. Turn individual packages on or off through the Sensor Management or Fleet Manager interface, tuning detection and enrichment coverage to what the environment requires.

Corelight_Hero_Platform--Build-your-platform

Maximize ROI with services and training from Corelight

Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.

  • Accelerate implementation and time to value with health checks

  • Precision engineering for detection calibration and customization

  • Expert-led training and education services

training-hero
 

FAQ