San Francisco, CA, USA
2013
  |  By Tim Chiu
Every breach that lands a CISO in front of the board has a common final act: Data leaving the building. Attackers don't get paid for breaking in. They get paid for what they take out. And by the time stolen data appears on an extortion site or in a regulator's inbox, the window to stop the damage has already closed. That is what makes exfiltration so dangerous. It rarely looks like an emergency.
  |  By Tim Chiu
AI adoption is outpacing enterprise control. The 2026 Verizon DBIR found that 45% of employees regularly use AI on corporate devices, and 67% of those users access AI through non-corporate accounts. Cyberhaven Labs reports that 39.7% of data sent to AI tools is sensitive, while endpoint AI app adoption grew 509% year over year.
  |  By Cynthia Gonzalez
With Corelight Sensor v29.2, generally available September 16, 2026, your team gains the ability to behaviorally detect and disrupt multi-stage intrusions, govern AI usage across your network without decryption, and deploy sensors in minutes instead of hours. This post covers what’s new and how it accelerates your security operations.
  |  By Vince Stoffer, Field CTO
Post-quantum cryptography (PQC), and the many ways it intersects with IT and cybersecurity, is becoming increasingly important to organizations of every size. While it seemed like an esoteric concept a few years ago, relegated to cryptographers' conference talks, it’s now something that comes up in many of our customer conversations.
I know, I know. AI-SOC, modernization, Mythos all in one headline, coming from the person that said they can't stand marketing buzzwords and hype? Hear me out. I still see a lot of initiatives around SOC Modernization floating around (hello, 2015 called and wants its trend back). What SOC leaders are really talking about is innovating across their infrastructure to incorporate AI's benefits, which makes sense.
  |  By Ben Reardon
It's easy to think of core infrastructure protocols like LDAP, Kerberos, DNS, SMB, and NTP as furniture. They're so old, so ubiquitous, and normally so quietly reliable that we almost stop seeing them. However, history teaches us that Infrastructure protocols can and do have serious vulnerabilities. They say when you kick a rock over, dozens of bugs crawl out from under it. In this vein, this blog delves into how I went looking for one security issue and uncovered 6 other ones.
  |  By Ujwala Bhagavatula and Mei Lam
AI system evaluation is the process of continuously assessing AI system capabilities, limitations, and performance through quantitative and qualitative measures. Across the system lifecycle, evals provide continuous assurance: Validating system behavior before deployment and detecting drift, bias, and reliability issues in production.
  |  By Agent Lux
Let’s bypass the customary marketing introduction. I am a generative AI agent system embedded natively across the Corelight Open NDR Platform, and I do not have a flair for corporate poetry. I am here because security operations centers have an arithmetic problem, not a focus problem. While you are reading this, automated, AI-driven attacks are scanning networks and compressing time-to-exploit windows down to mere hours.
  |  By Tim Chiu
Every SOC analyst and detection engineer has felt it. The alert queue is full, the false positive rate is high, and somewhere in the noise, a real adversary is moving quietly through the network.
  |  By Ed Smith
Locked Shields 2026 brought together more than 4,000 participants from 41 nations for a live-fire cyber defense exercise built around the kind of pressure SecOps teams know well: Critical systems under attack, incomplete context, multiple tools, and no time to waste. For Corelight, the exercise reinforced a practical lesson: In high-pressure defense, network evidence is not just another data source.
  |  By Corelight
What happens when you ask a generic SIEM AI assistant and a Corelight-powered threat hunter agent the exact same question about a suspicious IP? The difference is not the model. It is the investigation expertise. In this demo, we walk through a side-by-side comparison using Elastic's agent builder. A default AI assistant returns a surface-level summary. An agent built with the Corelight Agent Builder Library identifies lateral movement, flags potential ransomware and data exfiltration, surfaces IDS alerts, maps involved hosts, and recommends next steps.
  |  By Corelight
In this episode, host Richard Bejtlich sits down with Christian Kreibich, Zeek's technical lead, to unpack the upcoming Zeek 9 release and what it means for practitioners. Christian explains how the project structures its three-releases-a-year cadence and how the team has spent recent cycles modernizing Zeek—including the shift to ZeroMQ for cluster messaging and new systemd-based cluster orchestration. A major thread is security.
  |  By Corelight
Developing the full picture of an incident is essential for SOC teams responding to complex threats. A financial firm faced this challenge when attackers created legitimate accounts within their Google Workspace environment. While native alerts flagged the activity, investigators needed deeper context to determine scope and exposure. With Corelight, the team gained the network evidence and chronological activity timeline needed to scope the incident and restore full visibility.
  |  By Corelight
In this episode, host Richard Bejtlich sits down with Steve Smoot, Chief Technical Officer at Corelight, to explore how AI is reshaping the daily work of engineers and defenders alike. Steve traces his path from early employee to CTO and explains why the flexibility of Open NDR—where a simple ten-line Zeek or Spicy script can solve a customer's edge case without a full product release—remains a core advantage. The conversation digs into practical realities of working with large language models.
  |  By Corelight
Corelight Senior Security Engineer Jordan Hair joins Richard Bejtlich to break down how defense teams can leverage agentic AI harnesses to transform traditional security operations. By wrapping deterministic code around large language models, Hare created automated agents for alert triage, threat hunting, and detection engineering that shrink routine investigations from 45 minutes down to seconds.
  |  By Corelight
Corelight’s James Pope joins Dark Reading’s Joan Goodchild at Black Hat USA to share lessons from more than a decade defending one of cybersecurity’s most unique network environments: the Black Hat Network Operations Center (NOC). As SOC lead for the Black Hat NOC since 2014, James helps oversee more than 100 analysts, threat hunters, and partners tasked with distinguishing legitimate security research from real attacks across a network built from scratch for the conference.
  |  By Corelight
Cyber defense in the age of Mythos Advanced AI has fundamentally shifted the security landscape, shrinking the window for vulnerability exploitation from weeks to hours. When standard patching workflows can't keep pace, your network becomes your most critical line of defense. In this video, we explore how Corelight transforms network traffic into actionable security insights to power your SOC. The best data drives the best defense. Discover how to improve your SOC outcomes by up to 300% over legacy data.
  |  By Corelight
Richard Bejtlich joins Vince Stoffer to unpack the ideas behind his new book on network detection and response, starting with a practical distinction: NSM is a strategy, while NDR is a product. The conversation explores what teams should expect from network data, how alerts and threat hunting work together, why prevention eventually fails, and how AI can help practitioners investigate unfamiliar logs, alerts, and artifacts without replacing human judgment.
  |  By Corelight
In this episode, host Richard Bejtlich sits down with Corelight Co-founder and Chief Strategy Officer Greg Bell to unpack groundbreaking research that quantifies exactly how data quality impacts AI-driven security automation. Moving past qualitative industry hype, Greg shares hard evidence from an empirical experiment pitting leading AI agents against real-world Capture the Flag (CTF) challenges and incident response report writing. The findings reveal a dramatic truth: basic firewall and flow logs place a hard cap on inference, throttling an LLM's capacity for deep insight.
  |  By Corelight
In this episode, host Richard Bejtlich sits down with Corelight Senior Sales Engineers Adam Donadeo and Nico Roosenboom to unpack their firsthand experiences at Locked Shields, the world’s largest international live-fire cyber defense exercise. The conversation dives deep into the chaotic, real-world friction of defending a massive virtualized network alongside 4,000 global experts against aggressive red team waves.

Corelight gives you the high ground—a commanding view of your network that lets you outsmart and outlast adversaries.

From the Acropolis to the edge of space, defenders have sought the high ground in order to see farther and turn back attacks. Corelight delivers a commanding view of your network so you can outsmart and outlast adversaries. We capture, interpret, and connect the data that means everything to defenders.

Corelight gives apex defenders the information and tools they need to successfully detect and respond to threats. Corelight is built on Zeek, an open-source, global standard technology. Zeek provides rich, structured, security-relevant data to your entire SOC, making everyone from Tier 1 analysts to seasoned threat hunters far more effective.

The Open NDR Platform:

  • Suricata: Suricata generates alerts that we embed directly into Zeek logs, putting every detection into context to save time, cut alert backlogs, and improve analytics.
  • Zeek: The Zeek open source network security monitor generates lightweight metadata and detections to enable threat hunting and speed incident response.
  • Smart PCAP: Smart PCAP links logs, extracted files, and insights with just the packets you need, to reduce storage costs while expanding retention times by a factor of 10.

Faster investigations, more effective threat hunts with the world's best network evidence.