Corelight
Unleash powerful network security and analytics with Zeek-based insights.. [Contact for Pricing]
Last verified:
What is Corelight?
Corelight is an evidence-based network detection and response platform that turns network and cloud activity into security evidence for detection, investigation, and threat hunting. It emphasizes complete network visibility, AI-driven detection, and faster triage so security teams can see what is happening on their networks and respond with more confidence.
The platform centers on turning traffic into rich, correlated evidence rather than relying only on alerts. Corelight says this evidence supports AI-powered workflows, expert-authored playbooks, and an AI SOC ecosystem, with benefits such as faster triage, fewer false positives, and better context for investigations.
Corelight is built around an open NDR approach and is founded on Zeek, with deep integration of Suricata IDS and other evidence collections. Its product family includes Investigator, sensors, Smart PCAP, file analysis, cloud sensors, Fleet Manager, and multiple collections for encrypted traffic, C2 activity, entity inventory, and ICS/OT environments.
The platform is aimed at security operations teams, threat hunters, incident responders, and larger enterprises that need deep network telemetry across on-premises, cloud, and hybrid environments. Corelight also highlights fit for mission-critical organizations, including large enterprises, government, healthcare, manufacturing, and research institutions.
Corelight pricing
Pricing model: Freemium
Corelight does not publish standard pricing on the website. The contact page says customers can request pricing or a quote and request a demo, which suggests sales-led pricing rather than self-service checkout. The support page shows Standard and Enterprise support plans, and Technical Account Management is included in the subscription. The site also lists software updates, security bulletins, support portal access, and hardware replacement options in the plan comparison, but it does not disclose public tier prices or a free plan.
Corelight pros
- Complete network visibility
- Evidence-first investigation approach
- AI-driven detection workflows
- 10x faster triage claim
- Alert consolidation into evidence packages
- Lower false positives
- Rich network metadata capture
- Months of traffic history with Smart PCAP
- Open NDR architecture
- Built on Zeek
- Deep Suricata IDS integration
- Cloud sensor support for AWS, GCP, and Azure
- On-prem and cloud coverage
- Supports East-West and North-South traffic
- Fleet Manager for centralized sensor management
- Investigations without decryption for encrypted traffic insights
- ICS/OT protocol visibility
- Native integration with Splunk ES and Splunk SOAR
- CrowdStrike and Microsoft Defender ecosystem support
- Technical Account Management included in subscription
- 24 x 7 support available in enterprise plan
- Hardware and software sensor options
- High-throughput appliance models up to 100+ Gbps
- Open source and proprietary evidence collections
Corelight cons
- Pricing is not publicly listed
- No self-serve free tier shown
- Subscription-based procurement required
- Hardware may be needed for appliance deployments
- Some features depend on sensor placement and traffic access
- Advanced coverage may require enterprise integration work
- Best value is likely for larger security teams
- Not a lightweight consumer security tool
- Complex deployments may need technical expertise
Frequently asked questions about Corelight
What is Corelight?
Corelight is an evidence-based network detection and response platform that converts network and cloud activity into security evidence. It is designed to help teams detect threats, investigate incidents, and hunt for malicious activity using rich telemetry rather than only relying on isolated alerts.
What problem does Corelight solve?
Corelight helps security teams close visibility gaps, reduce false positives, and speed up triage and investigations. The platform focuses on turning raw traffic into correlated evidence so analysts can understand what happened, not just that something happened.
What products are included in the platform?
Corelight’s platform includes Investigator, Zeek, Suricata IDS, Smart PCAP, static file analysis, C2 Collection, Core Collection, Encrypted Traffic Collection, Entity Collection, ICS/OT Collection, Cloud Sensors, Software Sensor, Virtual Sensors, and Fleet Manager. The product set spans analytics, sensors, evidence collections, and management tools.
What is Investigator?
Investigator is Corelight’s SaaS-based network detection and response solution. The website describes it as an evidence-first threat investigation platform that simplifies Tier 1 workflows and helps teams move from alerts to ready-to-investigate evidence more quickly.
What makes Corelight different from basic network monitoring?
Corelight is built around evidence-based security rather than just packet capture or simple alerting. It correlates logs, files, signatures, and other network evidence so teams can investigate incidents with much more context.
Does Corelight work in the cloud?
Yes. Corelight offers Cloud Sensors and says its cloud security solutions can detect and respond to threats targeting cloud workloads. The site mentions support for AWS, GCP, and Azure, with both SaaS and self-managed options available.
Does Corelight support encrypted traffic analysis?
Yes. The Encrypted Traffic Collection provides insights into SSL, SSH, and RDP connections, including community-contributed signals like JA3, without requiring decryption. This is intended to help teams gain visibility into encrypted activity while preserving operational efficiency.
What kind of traffic history can Corelight keep?
The website says Smart PCAP can capture only the packets needed for investigations and store months, not minutes, of traffic history. Corelight also states that its evidence can go back months, which is useful for retrospective investigations.
How does Corelight support large security operations teams?
Corelight offers centralized sensor management through Fleet Manager, support for multiple sensor types, and integrations with platforms like Splunk, CrowdStrike, and Microsoft Defender. It also highlights Technical Account Management and enterprise support options for ongoing program success.
How do you buy Corelight?
The website directs interested buyers to contact Corelight for pricing or a quote and to request a demo. That indicates a sales-assisted purchasing model rather than a public self-service store with posted pricing.