Skip to main content
Corelight
Investigation and management

Investigator

SaaS NDR with AI/ML detections and Agentic Triage

Corelight Investigator is the SaaS console where a SOC team investigates network events with the evidence attached. Detections come from AI/ML models, behavioral analytics, signatures and threat intelligence, and analysts can save their own queries. Corelight reports coverage of more than 100 MITRE ATT&CK techniques. Agentic Triage runs every investigation through transparent, expert-written playbooks, reviews the last seven days of host activity and returns a summary with its reasoning chain and links to the underlying logs. Analysts ask questions in plain English instead of query syntax. From the same screen they isolate a host, block an IP or log a user out, and SIEM Verdict Export pushes each verdict into the SIEM. Triage runs up to 10 times faster, according to Corelight.

Security

Enterprise-grade protection compliant with regulatory requirements and security standards

Performance

Fast deployment with minimal resource overhead

Support

Dedicated support from a certified partner

Integration

Easy integration with your existing infrastructure

Key features

  • AI/ML, behavioral, signature and threat intel detections covering more than 100 MITRE ATT&CK techniques (Corelight data)
  • Agentic Triage with transparent expert playbooks, a seven-day review of host activity and an analyst-ready summary
  • Natural Language Query: questions in plain English instead of query syntax
  • Response from the console: host isolation, IP blocking and identity actions (logout, password reset, account disable) through integrated EDR, firewall and identity provider workflows
  • SIEM Verdict Export sends the verdict, reasoning chain and evidence links to your SIEM

Business benefits

  • Faster triage: up to 10 times faster and 3 times more cases per analyst, according to Corelight
  • Every verdict links to a log or packet, so the decision stands up in an audit or a post-incident review
  • Tier 1 analysts start from a finished summary instead of assembling context from several tools
  • Plain-English questions open network data to people who do not write queries
  • Detection and response in one workflow shortens the path from alert to closed incident
Corelight

Why Corelight?

Corelight is an Open NDR platform that turns network traffic into evidence your SOC can act on: Zeek logs, Suricata alerts, YARA file analysis and selective packet capture with Smart PCAP. Appliance, virtual, software and cloud sensors feed that evidence into Corelight Investigator or your own SIEM, where AI/ML detections and Agentic Triage shorten investigations.

All products

Need Investigator in your organization?

As a certified Corelight partner, we'll help you deploy and configure the solution.

Book a free consultation