OPEN NDR WITH NEXT-LEVEL ANALYTICS
Corelight Investigator combines the power of our Open NDR Platform with machine learning and other analytics into an easy-to-use, quick-to-deploy SaaS solution. We simplify SOC workflows to give your team valuable time back to triage and respond with confidence. Disrupt attacks by shifting from low-priority, reactive tasks to high-impact, proactive defense.

Dashboards put context first
Investigator's intuitive, out-of-the box dashboards make it easy to understand what's happening across your network—from on-prem to the cloud. Customize your dashboards to meet the unique needs of your organization.

Transparent + customizable
Want to see what's behind your detections? Investigator shows you exactly how machine learning detections are made. Corelight makes it easy to write new rules to adapt to your unique environment. Read the blog post.
Focus on alerts that matter
Increase SOC performance metrics and cut through the backlog with aggregated, prioritized alerts mapped to the MITRE ATT&CK® framework. Quickly access correlated evidence in just one click, driving faster decisions and response times.
FAQ
Not at all. Investigator complements your existing SOC workflow and tools including SIEMs, SOAR and XDR solutions. If you do not have a SIEM, we can make Investigator’s evidence and insights available to your data lake or other tools.
Of course. The built-in threat hunting queries and intuitive search capabilities can turn almost any Tier 1 analyst into a threat hunter. Investigator provides network evidence and advanced analytics to your entire team, from Tier 1s doing triage to hunters chasing nation-state actors.
Yes. Corelight is dedicated to making our products as open as possible. Plus, you can leverage the latest from the Zeek® and Suricata communities to further tune your analytics.
Both options leverage open source tools (Zeek® and Suricata) to transform network activity into powerful evidence. Investigator is optimized for SOCs that want its additional capabilities (including machine learning and behavioral analytics), and prefer a SaaS-based solution with built-in dashboards and queries.
Investigator is a SaaS-based solution that is sold as a subscription with various options for log-storage, services, and other features. Please contact us to get the latest quotes and pricing information.
ENVIRONMENTS
NEXT-LEVEL ANALYTICS