About Corelight
Corelight specializes in open network detection and response (NDR) solutions for large enterprises and government customers. Corelight reported significant growth, with an increase of over 40% in annual recurring revenue for the fiscal year ending on January 31st, 2024.
There are  main ways in which Corelight helps its customers. expand visibility into network.  improves detection coverage, thereby accelerating incident response process. foundations in the open source world (Zeek). Corelight makes it easy to adopt and scale Zeek for enterprise customers. Corelight helps reduce the false positives, which reduces the alert backlog and thus accelerates incident response process.
Corelight Solutions: The Opportunity Space
Corelight focuses on taking the pain out of deploying Zeek at enterprises and provides in-depth visibility. Corelight customers typically have three different types of analytics architecture. Corelight sells its solutions to match these data analytics architectures.
Customer Persona: Data lake architecture Customer Needs: These customers prefer to store all their data in a central repository and customize their own security workflows, automation and detection engineering. Corelight Solution: Sensor Portfolio that generates rich data, rich evidence, analytics and detections Customer Persona: SIEM and XDR  customers who need the network centric data and analytics but also need help with alert aggregations, tuning & triage. Typically do threat hunting and incidence response in XDR or SIEM tools. Corelight Solution: Sensor Portfolio + Analytics offering that goes on top of the sensors Customer Persona: Full Stack NDR (the SOC Triad) Customer Needs: customers who prefer to use EDR for endpoint detection, NDR for network incident response & threat hunting, and finally send alerts downstream to their SIEM Corelight Solution: Clorelight Investigator Differentiators
Classic Speeds and Feeds of the Sensors (has deployed and scaled solutions with upto 1 Tbps) Cloud/On-Prem/Hybrid Deployment models that align with customer preferred data-analytics architecture  Open Source heritage (CTO Vern Baxton founded Zeek in 1995) Best High-Quality Data (learning from high-end defenders, partnership with Mandiant & others),  Broad ecosystem (Zeek, Seracata, adoption of chatGPT to understand threats, community learnings & work that help accelerate threat detections) What is ?
Zeek is an open source network monitoring tool that was created in 1995 by  (co-founder of Corelight). Vern Paxson designed and implemented the initial version in 1995 as a researcher at the Lawrence Berkeley National Lab. Today, Corelight develops and sells an enterprise grade version of Zeek to large enterprises and governments. Zeek offers three key network security capabilities - traffic logging, file extraction and custom traffic analysis. Network or SOC engineers can look at the logs based on timestamp, connection identifier, protocols and so on to find meaningful insights. Zeek sensors are deployed out of band and the network traffic is captured and sent to Zeek sensors via a SPAN port or TAP. The network feed is turned to Zeek Logs, which can then be sent to SIEM or data lakes for analysis.