CONTACT US
forrester wave report 2023

Forrester rates Corelight a strong performer

GET THE REPORT

ad-nav-crowdstrike

Corelight now powers CrowdStrike solutions and services

READ MORE

ad-images-nav_0013_IDS

Alerts, meet evidence.

LEARN MORE ABOUT OUR IDS SOLUTION

ad-images-nav_white-paper

5 Ways Corelight Data Helps Investigators Win

READ WHITE PAPER

glossary-icon

10 Considerations for Implementing an XDR Strategy

READ NOW

ad-images-nav_0006_Blog

Don't trust. Verify with evidence

READ BLOG

ad-nav-NDR-for-dummies

NDR for Dummies

GET THE WHITE PAPER

video

The Power of Open-Source Tools for Network Detection and Response

WATCH THE WEBCAST

ad-nav-ESG

The Evolving Role of NDR

DOWNLOAD THE REPORT

ad-images-nav_0006_Blog

Detecting 5 Current APTs without heavy lifting

READ BLOG

g2-medal-best-support-ndr-winter-2024

Network Detection and Response

SUPPORT OVERVIEW

 

OPEN NDR PLATFORM

Corelight combines the best in open-source technologies, fusing Suricata alerts with Zeek network data, then adding Smart PCAP for complete threat investigation. 

WATCH DEMO

OPEN NDR PLATFORM

Corelight transforms network and cloud activity into evidence. Easily deployed and available in on-prem and SaaS-based formats, Corelight combines the power of open source and proprietary technologies to deliver a complete Open Network Detection & Response (NDR) Platform that includes intrusion detection (IDS), network security monitoring and Smart PCAP solutions.

WATCH DEMO

 

evidence-stack-diagram-NDR

 

 

NDR-icon

WHY OPEN NDR

Network Detection and Response platforms monitor and analyze network traffic, delivering telemetry into existing SIEM, XDR, or SaaS-based solutions. Corelight’s platform is unique because our detections and visibility engineering are community driven—with continuous content creation from Zeek®, Suricata IDS, and other Intel communities. And our integration with CrowdStrike XDR enables cross platform (EDR+NDR) analytics. This provides you with the most complete network visibility, powerful analytics, and threat hunting capabilities, and accelerates investigation across your entire kill chain.

 

The Open NDR Platform

HOW NDR WORKS

 

zeek-logo-horizontal

 

It starts with the right telemetry

Zeek is the gold standard in open source network security monitoring with more than 10,000 deployments worldwide.

ABOUT ZEEK

Correlate alerts & packets into evidence

Corelight’s platform fuses alerts and packets with rich, interconnected context to create a single source of truth that attackers cannot alter.
 
 
correlate_alerts

 

screens

 

Apply the right detection approach per threat

Leverage our machine learning, behavioral analytics, and other signatures to lower false positives and accelerate detection engineering response time.

 ANALYTICS & DETECTIONS
 

Automate core SOC capabilities

Our open core approach and broad integration strategy allows you to easily integrate Corelight data into existing SIEM, XDR, and SOAR solutions.

automation-large

 

REPORT

Get The Forrester Wave: Network Analysis And Visibility, Q2 2023 Report

Forrester rates Corelight a strong performer

Corelight received the highest scores possible in the criteria of

  • Detection fidelity
  • Egress and internal visibility
  • Cloud

forrester-wave-2023