Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Corelight Agent Builder Library: AI Investigation Demo

What happens when you ask a generic SIEM AI assistant and a Corelight-powered threat hunter agent the exact same question about a suspicious IP? The difference is not the model. It is the investigation expertise. In this demo, we walk through a side-by-side comparison using Elastic's agent builder. A default AI assistant returns a surface-level summary. An agent built with the Corelight Agent Builder Library identifies lateral movement, flags potential ransomware and data exfiltration, surfaces IDS alerts, maps involved hosts, and recommends next steps.

Episode 23 - Inside Zeek 9: Modernizing Open Source Network Monitoring & Agentic Security Scanning

In this episode, host Richard Bejtlich sits down with Christian Kreibich, Zeek's technical lead, to unpack the upcoming Zeek 9 release and what it means for practitioners. Christian explains how the project structures its three-releases-a-year cadence and how the team has spent recent cycles modernizing Zeek—including the shift to ZeroMQ for cluster messaging and new systemd-based cluster orchestration. A major thread is security.

Financial Firm Stops Identity Attack in Under 2 Hours

Developing the full picture of an incident is essential for SOC teams responding to complex threats. A financial firm faced this challenge when attackers created legitimate accounts within their Google Workspace environment. While native alerts flagged the activity, investigators needed deeper context to determine scope and exposure. With Corelight, the team gained the network evidence and chronological activity timeline needed to scope the incident and restore full visibility.

Episode 22 - The CTO's Case for AI: Fixing Bugs, Vibe Coding, and the Future of Dev Jobs

In this episode, host Richard Bejtlich sits down with Steve Smoot, Chief Technical Officer at Corelight, to explore how AI is reshaping the daily work of engineers and defenders alike. Steve traces his path from early employee to CTO and explains why the flexibility of Open NDR—where a simple ten-line Zeek or Spicy script can solve a customer's edge case without a full product release—remains a core advantage. The conversation digs into practical realities of working with large language models.

Episode 21 - Building AI Harnesses to Unify Detection and Response

Corelight Senior Security Engineer Jordan Hair joins Richard Bejtlich to break down how defense teams can leverage agentic AI harnesses to transform traditional security operations. By wrapping deterministic code around large language models, Hare created automated agents for alert triage, threat hunting, and detection engineering that shrink routine investigations from 45 minutes down to seconds.

Securing Black Hat's NOC: Lessons from James Pope of Corelight

Corelight’s James Pope joins Dark Reading’s Joan Goodchild at Black Hat USA to share lessons from more than a decade defending one of cybersecurity’s most unique network environments: the Black Hat Network Operations Center (NOC). As SOC lead for the Black Hat NOC since 2014, James helps oversee more than 100 analysts, threat hunters, and partners tasked with distinguishing legitimate security research from real attacks across a network built from scratch for the conference.

Mythos: When Al becomes the attacker, the network becomes the first line of defense.

Cyber defense in the age of Mythos Advanced AI has fundamentally shifted the security landscape, shrinking the window for vulnerability exploitation from weeks to hours. When standard patching workflows can't keep pace, your network becomes your most critical line of defense. In this video, we explore how Corelight transforms network traffic into actionable security insights to power your SOC. The best data drives the best defense. Discover how to improve your SOC outcomes by up to 300% over legacy data.

Episode 20 - NDR Essentials: Why Network Data Still Defines Detection

Richard Bejtlich joins Vince Stoffer to unpack the ideas behind his new book on network detection and response, starting with a practical distinction: NSM is a strategy, while NDR is a product. The conversation explores what teams should expect from network data, how alerts and threat hunting work together, why prevention eventually fails, and how AI can help practitioners investigate unfamiliar logs, alerts, and artifacts without replacing human judgment.

Episode 19 - The Cap on Inference: Proving How Network Data Quality Drives AI Security ROI

In this episode, host Richard Bejtlich sits down with Corelight Co-founder and Chief Strategy Officer Greg Bell to unpack groundbreaking research that quantifies exactly how data quality impacts AI-driven security automation. Moving past qualitative industry hype, Greg shares hard evidence from an empirical experiment pitting leading AI agents against real-world Capture the Flag (CTF) challenges and incident response report writing. The findings reveal a dramatic truth: basic firewall and flow logs place a hard cap on inference, throttling an LLM's capacity for deep insight.

Episode 18 - Live Fire Defense at Locked Shields

In this episode, host Richard Bejtlich sits down with Corelight Senior Sales Engineers Adam Donadeo and Nico Roosenboom to unpack their firsthand experiences at Locked Shields, the world’s largest international live-fire cyber defense exercise. The conversation dives deep into the chaotic, real-world friction of defending a massive virtualized network alongside 4,000 global experts against aggressive red team waves.