Skip to main content
Corelight
Detection collections

Entity Collection

Inventory of hosts, devices, services and apps

Corelight Entity Collection builds an inventory of what is really on the network from observed traffic alone. It has three packages: Known Entities, Application Identification and Local Subnets. Known Entities keeps compact logs of hosts, devices, services, names, domains, certificates and users, and optionally remote hosts, though that log is off by default. ICWT enables the collection and connects it to your CMDB or SIEM. Application Identification recognizes more than 80 application types according to Corelight, from DNS queries, certificate SNIs and protocol metadata, and writes the result into a connection log field. Local Subnets discovers new local subnets as they appear. Analysts can then answer questions such as which hosts used SSH in the last 24 hours with a simple query.

Security

Enterprise-grade protection compliant with regulatory requirements and security standards

Performance

Fast deployment with minimal resource overhead

Support

Dedicated support from a certified partner

Integration

Easy integration with your existing infrastructure

Key features

  • Three packages: Known Entities, Application Identification and Local Subnets
  • Entity logs for hosts, devices, services, names, domains, certificates, users and, optionally, remote hosts (that log is off by default)
  • More than 80 application types recognized from DNS, certificates and protocol metadata (Corelight data), written into the connection log
  • Automatic discovery of new local subnets
  • Change tracking over time: new entities and shifts in known behavior

Business benefits

  • The inventory includes unmanaged devices, IoT and shadow IT that never made it into the CMDB
  • A fast answer to whether a high-value asset was targeted or produced unusual traffic
  • Application context in every connection log without manual enrichment
  • Support for the asset inventory work that NIS2 and DORA compliance programs require
  • Less manual list-building for analysts who used to assemble these inventories themselves
Corelight

Why Corelight?

Corelight is an Open NDR platform that turns network traffic into evidence your SOC can act on: Zeek logs, Suricata alerts, YARA file analysis and selective packet capture with Smart PCAP. Appliance, virtual, software and cloud sensors feed that evidence into Corelight Investigator or your own SIEM, where AI/ML detections and Agentic Triage shorten investigations.

All products

Need Entity Collection in your organization?

As a certified Corelight partner, we'll help you deploy and configure the solution.

Book a free consultation