- Home
- Network Security
- Network Detection and Response
- Corelight Smart PCAP
Corelight Smart PCAP
Selective packet capture linked to Zeek logs for investigation workflows

Corelight Smart PCAP
Selective packet capture linked to Zeek logs for investigation workflows
Go Beyond the Directory. Track the Entire Market.
Monitor competitor funding, hiring signals, product launches, and market movements across the whole industry.
Corelight Smart PCAP Description
Corelight Smart PCAP is a selective packet capture solution that links Zeek logs, detections, and extracted files to captured network packets. The product captures only relevant packets based on configurable rules rather than storing full packet captures, extending lookback windows by up to 10x compared to full PCAP storage. The solution operates through Corelight Sensors deployed in the network environment. Analysts can configure capture rules at adjustable byte-depths based on triggers including alerts, protocol type, and encryption status. The system supports multiple storage options including Corelight hardware, customer-provided hardware, or cloud storage via Amazon S3. Smart PCAP embeds PCAP URLs directly in connection logs, enabling analysts to retrieve packets with one-click access from their SIEM or Corelight Investigator. Retrieved packets open in Wireshark for analysis. The product can be configured to capture packets for all connections not already captured via Corelight logs, and can capture the first 2,000 bytes of all unencrypted traffic. The selective capture approach reduces storage requirements while maintaining network visibility by providing evidence for every connection through Corelight logs, captured packets, or both. The sensor management console provides centralized control for creating and managing capture rules across the deployment.
Corelight Smart PCAP FAQ
Common questions about Corelight Smart PCAP including features, pricing, alternatives, and user reviews.
Corelight Smart PCAP is Selective packet capture linked to Zeek logs for investigation workflows developed by Corelight. It is a Network Security solution designed to help security teams with Packet Capture, Network Traffic Analysis, Zeek.
FEATURED
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
Cybercrime intelligence tools for searching compromised credentials from infostealers
Password manager with end-to-end encryption and identity protection features
Fractional CISO services for B2B companies to build security programs
POPULAR
Real-time OSINT monitoring for leaked credentials, data, and infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox