- Home
- Network Security
- Network Detection and Response
- Corelight Core Collection
Corelight Core Collection
Analytics collection for Zeek-based NDR with threat detection & data controls

Corelight Core Collection
Analytics collection for Zeek-based NDR with threat detection & data controls
Go Beyond the Directory. Track the Entire Market.
Monitor competitor funding, hiring signals, product launches, and market movements across the whole industry.
Corelight Core Collection Description
Corelight Core Collection is an analytics package included with Corelight subscriptions that extends the Open NDR Platform with threat detection capabilities and data optimization features. The collection provides analytics developed by the Zeek community for detecting lateral movement, port scanning, cryptomining, HTTP stalling attacks, and long-running connections. The product includes enrichment capabilities that add context to network evidence, such as Community ID hashing for connection correlation across tools, DNS hostname annotation in connection logs, POST data capture in HTTP logs, URL extraction from email bodies, and Windows version identification from HTTP headers. Data control features help optimize SIEM performance and costs through configurable data reduction options that can shrink export volumes by up to 30% by filtering data of minimal security value from connection, HTTP, DNS, and SSL logs. Traffic shunting capabilities allow organizations to conserve sensor processing bandwidth by filtering unwanted traffic flows at the network interface card level. The lateral movement detection component implements MITRE BZAR analytics to identify techniques related to SMB and DCE-RPC traffic, including indicators targeting Windows Admin Shares and Remote File Copy. The collection can be enabled or disabled through Corelight Sensor Management and Fleet Management interfaces.
Corelight Core Collection FAQ
Common questions about Corelight Core Collection including features, pricing, alternatives, and user reviews.
Corelight Core Collection is Analytics collection for Zeek-based NDR with threat detection & data controls developed by Corelight. It is a Network Security solution designed to help security teams with Zeek, Threat Detection, Network Traffic Analysis.
FEATURED
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
Cybercrime intelligence tools for searching compromised credentials from infostealers
Password manager with end-to-end encryption and identity protection features
Fractional CISO services for B2B companies to build security programs
POPULAR
Real-time OSINT monitoring for leaked credentials, data, and infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox