Skip to main content
Corelight
Detection collections

Encrypted Traffic Collection

SSL, SSH, RDP and VPN insight without decryption

Corelight Encrypted Traffic Collection is a set of analytics that draws conclusions from encrypted connections without decrypting them. The sensor works from observable traits such as timing and packet sizes and compares them with known protocol behavior. For SSH it recognizes interactive sessions with keystrokes, file transfers, scanning, brute force logins, tunneling and port forwarding, reverse tunnels and stepping-stone chains across servers. For TLS it tracks certificate hygiene: newly issued and expiring certificates, and weak keys. For RDP it infers the client, the authentication outcome and session behavior. It also detects DNS over HTTPS, adds VPN insights and writes JA3/JA3S and HASSH fingerprints into the Zeek logs.

Security

Enterprise-grade protection compliant with regulatory requirements and security standards

Performance

Fast deployment with minimal resource overhead

Support

Dedicated support from a certified partner

Integration

Easy integration with your existing infrastructure

Key features

  • SSH inferences: interactive sessions, file transfers, scanning, brute force, tunneling, reverse tunnels, stepping stones
  • TLS certificate hygiene: newly issued, expiring and weak-key certificates
  • RDP inferences from client, authentication and session behavior
  • DNS over HTTPS detection and VPN insights
  • JA3/JA3S fingerprints for TLS and HASSH fingerprints for SSH, written into the Zeek logs

Business benefits

  • Catch abuse in encrypted traffic without TLS inspection, so you avoid the hardware cost and the privacy debate
  • Earlier detection of lateral movement over SSH and RDP, a standard stage of ransomware attacks
  • Misconfigurations that expose data come to light before an attacker finds them
  • Ready-made Zeek log fields your team can turn into its own SIEM rules
  • An answer for auditors: oversight of encrypted traffic without touching the content
Corelight

Why Corelight?

Corelight is an Open NDR platform that turns network traffic into evidence your SOC can act on: Zeek logs, Suricata alerts, YARA file analysis and selective packet capture with Smart PCAP. Appliance, virtual, software and cloud sensors feed that evidence into Corelight Investigator or your own SIEM, where AI/ML detections and Agentic Triage shorten investigations.

All products

Need Encrypted Traffic Collection in your organization?

As a certified Corelight partner, we'll help you deploy and configure the solution.

Book a free consultation