Corelight
Corelight makes sense of traffic in the cloud, fast.
Corelight is the commercial version of open-source Bro (now Zeek) and is the most powerful network visibility solution available today.
Corelight converts network traffic into 50+ highly enriched logs (Zeek, FKA Bro) across 35+ protocols. Being agnostic to SIEM, Data lake, and analysis tools, our open framework is an ideal compliment to any IR, MDR, or threat hunting team.

NTA (Network Traffic Analyser)
- Form factors are cloud, virtual and appliance
- Sizing based on throughput

Corelight Fleet Manager
- Single pane of glass to manage up to 250 corelight sensors (NTA’s)
Learn More
Download these resources to get more information on Corelight products and services

Understanding exactly why Zeek / Bro is so much more poweful than what you’re using now can be complex. This white paper illustrates five examples that show specifically how and why Corelight lets you resolve issues that can’t be resolved using traditional methods like Netflow and PCAP.

Your next security investment should maximise attack surface coverage, deploy fast, generate reliable data, and (ideally) have zero impact on operations. Corelight excels on all counts.

If your typical response to alerts involves digging through piles of PCAP files or trying to piece together data through thin NetFlow records, there’s a better way.