Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Paid
Claimed

Corelight Reviews & Product Details

Corelight Overview

What is Corelight?

Corelight's Open Network Detection and Response (NDR) Platform improves network detection coverage, accelerates incident response, and reduces operational costs by consolidating NDR, intrusion detection (IDS), and PCAP functionality in a single solution and by providing security analysts with machine learning-assisted investigations and one-click-pivots from prioritized alerts to the evidence needed to investigate and remediate them. Network Detection and Response platforms monitor and analyze network traffic, delivering telemetry into existing SIEM, XDR, or SaaS-based solutions. Corelight’s platform is unique because our detections and visibility engineering are community driven—with continuous content creation from Zeek®, Suricata IDS, and other Intel communities. And our integration with CrowdStrike XDR enables cross platform (EDR+NDR) analytics. This provides you with the most complete network visibility, powerful analytics, and threat hunting capabilities, and accelerates investigation across your entire kill chain. Corelight also delivers a comprehensive suite of network security analytics that help organizations identify more than 75 adversarial TTPs across the MITRE ATT&CK® spectrum including Exfiltration, Command and Control (C2), and Lateral Movement. These detections reveal known and unknown threats via hundreds of unique insights and alerts across machine learning, behavioral analysis, and signature-based approaches. CORELIGHT PRODUCTS + SERVICES Open NDR Platform Appliance, Cloud, Software, Virtual and SaaS Sensors IDS Fleet Manager Investigator Threat Hunting Platform Smart PCAP Corelight Training CERTIFICATIONS FIPS 140-2

Corelight Details
Product Website
Languages Supported
English
Show LessShow More
Product Description

Corelight provides security teams with network evidence so they can protect the world’s most critical organizations and companies. On-prem and in the cloud, our Open Network Detection and Response Platform enhances visibility and analytics, leading to faster investigations and expanded threat hunting. Corelight’s global customers include Fortune 500 companies, major government agencies, and large research universities. Based in San Francisco, Corelight is an open-core security company founded by the creators of Zeek®, the widely-used network security technology.


Seller Details
Seller
Corelight
Company Website
Year Founded
2013
HQ Location
San Francisco, CA
Twitter
@corelight_inc
4,223 Twitter followers
LinkedIn® Page
www.linkedin.com
325 employees on LinkedIn®
Description

Corelight is a cybersecurity vendor that specializes in providing advanced network visibility and threat detection solutions. Leveraging open-source technology, particularly Zeek (formerly known as Bro), Corelight offers tools that enable organizations to analyze and respond to security incidents effectively. Their platform helps businesses gain insights into network traffic, detect breaches, and enhance their overall security posture. For more information, visit their website at https://www.corelight.com/.


CM
Overview Provided by:

Recent Corelight Reviews

William J.
WJ
William J.Enterprise (> 1000 emp.)
4.5 out of 5
"We use Corelight sensors in our environment to monitor and alert based off of traffic."
Being able to enrich data daily as it is ingested and feed that into a log agrigator has been extremly useful. Depoloyments in our environment have...
Verified User
U
Verified UserMid-Market (51-1000 emp.)
4.0 out of 5
"Great Threat hunting choice"
Really good detection of threats and detailed informs, as a simple user this is super insightful
Verified User
A
Verified UserEnterprise (> 1000 emp.)
4.0 out of 5
"Pretty straight forward"
Great place for your cybersecurity needs!
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
1 person requested security information

Corelight Media

Corelight Demo - Corelight Investigator: Gain visibility across your hybrid and multi-cloud environment.
Investigator's out-of-the-box dashboards accelerate incident response by providing prioritized alerts and a one-click-pivot to the context required for triage.
Corelight Demo - Corelight Investigator: Accelerate response with alerts mapped to the MITRE ATT&CK® Framework.
Increase SOC performance metrics and cut through the backlog with aggregated, prioritized alerts mapped to the MITRE ATT&CK Framework. Quickly access correlated evidence in just one click, driving faster decisions and response times.
Corelight Demo - Corelight Investigator: Improve cybersecurity through transparency.
Understand the logic behind the detections. Corelight provides transparency behind the machine learning to provide additional context.
Corelight Demo - Corelight Smart PCAP
Store packets longer and find them faster. Smart PCAP is a highly efficient approach to packet capture that links Zeek® logs, extracted files, and detections with just the packets you need for investigation. Corelight's Smart PCAP gives security teams complete control over packet capture. Comp...
Corelight Demo - Corelight Fleet Manager
Corelight Fleet Manager ensures seamless support and administration for multiple Corelight Sensors throughout an organization, providing single management dashboard with RBAC, customizable configuration templates, and sensor health and performance monitoring. The Corelight Fleet Manager dashboard...

Official Downloads

Answer a few questions to help the Corelight community
Have you used Corelight before?
Yes

20 Corelight Reviews

4.6 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
20 Corelight Reviews
4.6 out of 5
20 Corelight Reviews
4.6 out of 5

Corelight Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for CorelightQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
William J.
WJ
Security Analyst
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

Being able to enrich data daily as it is ingested and feed that into a log agrigator has been extremly useful. Depoloyments in our environment have also gone smoothly and the price has been fair. Review collected by and hosted on G2.com.

What do you dislike about Corelight?

One of the few downsides I have noticed is that we have had to write some corelight modules ourselves to properly sort and ingest data. Review collected by and hosted on G2.com.

What problems is Corelight solving and how is that benefiting you?

Corelight allows us to monitor our internal traffic and alert off of supicious traffic. Without this we would be largely blind in our internal environment to what traffic is going where in any kind of meaningful way. Review collected by and hosted on G2.com.

LS
Sr. Devops Engineer
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

My most helpful about corelight is network detection and analyze. Review collected by and hosted on G2.com.

What do you dislike about Corelight?

I would like more UI experience and improve it I would say. Review collected by and hosted on G2.com.

What problems is Corelight solving and how is that benefiting you?

Business problems corelight is solving and thats directly benifiting company on major finance and in aws marketplace, Incident response. Review collected by and hosted on G2.com.

Verified User in Market Research
UM
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

Really good detection of threats and detailed informs, as a simple user this is super insightful Review collected by and hosted on G2.com.

What do you dislike about Corelight?

I would like the detection of threat be faster but i know there are some process to accomplish before i could reicive the results. Review collected by and hosted on G2.com.

What problems is Corelight solving and how is that benefiting you?

Give me an interface with almost everything that i need to do much easier to detect anomalies Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

1) Clean Website UI

2)Services provided

3) It seems very easy to use the services Review collected by and hosted on G2.com.

What do you dislike about Corelight?

Not much popularity

To much techinal features in the website that would be overwhelming for someone who is not involved in the field Review collected by and hosted on G2.com.

What problems is Corelight solving and how is that benefiting you?

It helps me to easliy track and monitor my AWS resources Review collected by and hosted on G2.com.

Richard D.
RD
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Corelight?

The support and periodic review with the team assigned to you are excellent. The product (sensor AP along with add-ons such as Suricata and machine-based learning that provide insights within the Crowdstrike (Humio) platform are excellent. The base platform is like Zeek on steriods. If needed,pro-active support even lets you know the hardware may be failing and an RMAs you an identical substitute. The device logs to Humio, syslog, etc. simultaneously

The command line control of the device is excellent, and so is fleet management for a series of APs. There is also an annual Zeek conference in which new insights and roadmaps are presented by Corelight Review collected by and hosted on G2.com.

What do you dislike about Corelight?

Nothing - the sensors work perfectly and dashboard summaries are very good. If one wants, one can always simply query the data manually. There is constant improvement with the release of updates and integrations with other vendor products. Corelight support is always helpful no matter what I throw at them - ranging from technical questions down to annual quotes to renew licenses. I simply cannot find anything to dislike Review collected by and hosted on G2.com.

What problems is Corelight solving and how is that benefiting you?

Pro-active security monitoring and if there is penetration, one can look back to trace the origins. I am far more productive than I was without using Corelight. Review collected by and hosted on G2.com.

Verified User in Consulting
AC
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

Great place for your cybersecurity needs! Review collected by and hosted on G2.com.

What do you dislike about Corelight?

Partnered with crowstrike and the uncertainty with those two combined. Review collected by and hosted on G2.com.

What problems is Corelight solving and how is that benefiting you?

Their system is very great detection system Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
AC
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Corelight?

Very easy to deploy. The hardware sensors and pre-made VM images make deployment as an MSSP very easy as we can just hand this stuff to the customer and give them the key to our Fleet Manager and manage the rest on our side.

Fleet Manager in particular is really good for managing disparate configurations and one-offs across multiple customers. Review collected by and hosted on G2.com.

What do you dislike about Corelight?

I'd say Fleet Manager not having the ability to facilitate the particular MSSP scenario where the MSSP owns Fleet Manager and has a variety of customers in one instance, but the customer wants access to Fleet Manager for reporting or perhaps editing configurations. Because we can't silo customers in like a "site" fashion to prevent them from seeing other customer's data, it's a scenario we can't do right now. Review collected by and hosted on G2.com.

What problems is Corelight solving and how is that benefiting you?

I'd say most customers have an idea of how much traffic they've got, but not the composition of it. That rich NTA data central to Corelight is the main value I've seen for the customer's side. Review collected by and hosted on G2.com.

Swetha Y.
SY
Azure Data Engineer
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

Corelight helps you to find any bad things happening like sneaky viruses or hackers trying to get in and having a detective tool for our Network. So, that we can process Everything safe and run smoothly Review collected by and hosted on G2.com.

What do you dislike about Corelight?

The potential downsides of Corelight is that it can be complex to setup and manage and it might require specialized knowledge to use effectively and it needs to be improved for better usages. Review collected by and hosted on G2.com.

What problems is Corelight solving and how is that benefiting you?

Corelight helps find bad things happening on computer networks.It watches the network traffic and tells us if there are any suspicious activities. With this we can secure the systems safe and secure. Review collected by and hosted on G2.com.

Verified User in Higher Education
AH
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Corelight?

Corelight appliances do one thing and do it well: process your network traffic through analysis engines. Corelight support staff know what they're doing, reply promptly, and resolve most issues within two emails. Review collected by and hosted on G2.com.

What do you dislike about Corelight?

We've seen Corelight grow quite a bit since we first became a customer. I worry they might one day adopt Cisco's strategy of adding unnecessary features in the pursuit of achieving vendor lock-in. Doing would degrade the user experience and price out customers who can't afford a one-stop-shop security solution. Review collected by and hosted on G2.com.

What problems is Corelight solving and how is that benefiting you?

Corelight solves the problem of having to maintain the physical and application layers of a network traffic analysis tool. This frees up our engineers to concentrate on configuring Zeek and Suricata, in turn improving the quality of the data used by our SOC. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
UC
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: Seller invite
Incentivized Review
What do you like best about Corelight?

If your SOC needs better visibility, in particular in a way that will integrate with any of the other tools in your security stack, Corelight is the way to do it. In 15 minutes you can turn a network tap into rich metadata about every packet that's crossed that wire, in an open source format that works with any SIEM, schema, or other setup that might be valuable to you. Their Suricata integration is also the best IDS setup on the modern market, and their customer support is second to none. You'll be glad to work with Corelight, both the tech and the people! Review collected by and hosted on G2.com.

What do you dislike about Corelight?

Corelight is best suited for larger organizations. The cost to ingest data into SIEMs whose pricing model runs on ingest can be high, and less advanced SOCs will have a learning curve using the tool. Review collected by and hosted on G2.com.

What problems is Corelight solving and how is that benefiting you?

I can triage alerts much more rapidly, and I have a better asset inventory than ever before. It's a source of truth that has a lot of applications - there are plenty more than I'm using it for, for sure! Review collected by and hosted on G2.com.