Skip to main content
Corelight
Investigation and management

Smart PCAP

Rule-based selective packet capture

Corelight Smart PCAP records packets by rule instead of storing every byte that crosses the wire. You decide what goes to disk: IP addresses, ports, protocols or events raised by Zeek and Suricata. ICWT sets the capture rules and the retention policy together with your team. Each Zeek connection log gains an spcap.url field, so an analyst pulls the exact packets from the SIEM or from the Investigator console with one click. According to Corelight, this extends retention from days to weeks or months while lowering storage costs. Packets can live on local disk, an iSCSI array, AWS S3, Azure Blob or Google Cloud Storage. Downloads sit behind authentication and allow or deny lists, so sensitive traffic stays with authorized staff.

Security

Enterprise-grade protection compliant with regulatory requirements and security standards

Performance

Fast deployment with minimal resource overhead

Support

Dedicated support from a certified partner

Integration

Easy integration with your existing infrastructure

Key features

  • Capture rules based on IP addresses, ports, protocols and Zeek or Suricata events
  • An spcap.url field in every Zeek connection log opens the packets from the SIEM or the Investigator console
  • Storage on local disk, iSCSI, AWS S3, Azure Blob or Google Cloud Storage
  • Community ID correlation keeps packets and metadata tied to the same connection
  • Authentication plus allow and deny lists control who can download packets

Business benefits

  • Longer traffic history: retention grows from days to weeks or months, according to Corelight
  • Lower storage bills because only packets tied to investigations reach the disk
  • Packet-level proof in seconds, without searching a full capture
  • Sensitive packets stay with authorized people, which limits data leakage risk
  • Forensic material for investigators, insurers or regulators after a serious incident
Corelight

Why Corelight?

Corelight is an Open NDR platform that turns network traffic into evidence your SOC can act on: Zeek logs, Suricata alerts, YARA file analysis and selective packet capture with Smart PCAP. Appliance, virtual, software and cloud sensors feed that evidence into Corelight Investigator or your own SIEM, where AI/ML detections and Agentic Triage shorten investigations.

All products

Need Smart PCAP in your organization?

As a certified Corelight partner, we'll help you deploy and configure the solution.

Book a free consultation