Corelight Core Collection Logo

Corelight Core Collection

Analytics collection for Zeek-based NDR with threat detection & data controls

Visit website
Claim and verify your listing
0
CybersecRadarsCybersecRadars

Go Beyond the Directory. Track the Entire Market.

Monitor competitor funding, hiring signals, product launches, and market movements across the whole industry.

Competitor Tracking·Funding Intelligence·Hiring Signals·Real-time Alerts

Corelight Core Collection Description

Corelight Core Collection is an analytics package included with Corelight subscriptions that extends the Open NDR Platform with threat detection capabilities and data optimization features. The collection provides analytics developed by the Zeek community for detecting lateral movement, port scanning, cryptomining, HTTP stalling attacks, and long-running connections. The product includes enrichment capabilities that add context to network evidence, such as Community ID hashing for connection correlation across tools, DNS hostname annotation in connection logs, POST data capture in HTTP logs, URL extraction from email bodies, and Windows version identification from HTTP headers. Data control features help optimize SIEM performance and costs through configurable data reduction options that can shrink export volumes by up to 30% by filtering data of minimal security value from connection, HTTP, DNS, and SSL logs. Traffic shunting capabilities allow organizations to conserve sensor processing bandwidth by filtering unwanted traffic flows at the network interface card level. The lateral movement detection component implements MITRE BZAR analytics to identify techniques related to SMB and DCE-RPC traffic, including indicators targeting Windows Admin Shares and Remote File Copy. The collection can be enabled or disabled through Corelight Sensor Management and Fleet Management interfaces.

Corelight Core Collection FAQ

Common questions about Corelight Core Collection including features, pricing, alternatives, and user reviews.

Corelight Core Collection is Analytics collection for Zeek-based NDR with threat detection & data controls developed by Corelight. It is a Network Security solution designed to help security teams with Zeek, Threat Detection, Network Traffic Analysis.

Have more questions? Browse our categories or search for specific tools.

FEATURED

Heeler Application Security Auto-Remediation Logo

Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

Mandos Fractional CISO Logo

Fractional CISO services for B2B companies to build security programs

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

13
OSINTLeak Real-time OSINT Leak Intelligence Logo

Real-time OSINT monitoring for leaked credentials, data, and infrastructure

8
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

6
TestSavant AI Security Assurance Platform Logo

AI security assurance platform for red-teaming, guardrails & compliance

5
Mandos Brief Logo

Weekly cybersecurity newsletter covering security incidents, AI, and leadership

5
View Popular Tools →

Stay Updated with Mandos Brief

Get strategic cybersecurity insights in your inbox