Skip to main content
Corelight
Investigation and management

Open NDR Platform

Network detection and response built on Zeek and Suricata, with the evidence to back every alert

Corelight Open NDR Platform turns network traffic into evidence a security team can act on. Passive Corelight sensors produce Zeek logs, Suricata alerts, YARA file analysis results and selective Smart PCAP captures from the same traffic. The figures on this page are Corelight's own: the platform writes more than 70 protocol log types, and built-in log reduction typically trims data volume by 30 to 50 percent without dropping security metadata. Every Suricata alert carries the same identifier as its Zeek connection log, so analysts get context without stitching sources together. ICWT sizes the sensor architecture around your network topology. The evidence flows into Corelight Investigator or into the SIEM you already run: Splunk, Microsoft Sentinel, CrowdStrike Next-Gen SIEM, Google Security Operations, Elastic Security or SentinelOne Singularity.

Security

Enterprise-grade protection compliant with regulatory requirements and security standards

Performance

Fast deployment with minimal resource overhead

Support

Dedicated support from a certified partner

Integration

Easy integration with your existing infrastructure

Key features

  • Open source foundation: Zeek for network security monitoring and Suricata IDS, packaged and supported as one platform
  • More than 70 protocol log types (Corelight data), including HTTP, DNS and TLS, ready to search in your SIEM
  • YARA analysis of files extracted from traffic, plus Smart PCAP selective packet capture for forensics
  • Detection layers: machine learning models, behavioral analytics, curated signatures and threat intelligence, each tied to log evidence
  • Native exporters and apps for Splunk, Microsoft Sentinel, CrowdStrike Next-Gen SIEM, Google Security Operations, Elastic Security and SentinelOne Singularity

Business benefits

  • One source of network evidence for the SOC, threat hunting and forensics, wherever the sensor sits
  • Less data in the SIEM: Corelight reports typical log volume 30 to 50 percent lower with built-in reduction
  • Four tools in one: NSM, IDS, file analysis and packet capture, a 4:1 consolidation according to Corelight
  • Open data formats keep your team free to work in the SIEM it already owns instead of a closed console
  • A durable record of network activity, useful when documenting incidents, including NIS2 and DORA compliance programs
Corelight

Why Corelight?

Corelight is an Open NDR platform that turns network traffic into evidence your SOC can act on: Zeek logs, Suricata alerts, YARA file analysis and selective packet capture with Smart PCAP. Appliance, virtual, software and cloud sensors feed that evidence into Corelight Investigator or your own SIEM, where AI/ML detections and Agentic Triage shorten investigations.

All products

Need Open NDR Platform in your organization?

As a certified Corelight partner, we'll help you deploy and configure the solution.

Book a free consultation