Network detection and response built on Zeek providing rich network evidence for security teams.
Corelight transforms network traffic into rich, actionable evidence that security teams use to detect attacks, investigate incidents, and hunt for threats. Built on the open-source Zeek framework, Corelight sensors provide the deepest network visibility available — logs, extracted files, and protocol-level metadata — integrated with your SIEM, XDR, or data lake.