San Francisco, CA, USA
2013
  |  By Alyssa Ideboen
A SOC analyst spots suspicious activity from an internal IP. They need to understand what is happening. They open their SIEM's built-in AI assistant and type: "Tell me about 192.168.0.10." The assistant checks the entity store. Nothing. The analyst rephrases: "This is in our environment. Can you please check the logs and walk me through what's going on with this device?" A moment later, the assistant returns a summary. The host is involved in Windows file sharing and remote administration.
Citrix’s security bulletin CTX697096, the NetScaler security blog, and WatchTowr’s vulnerability FAQ describe an urgent situation for organizations using NetScaler ADC and NetScaler Gateway. Two vulnerabilities (CVE-2026-88771 and CVE-2026-88772) are known to be exploited. CISA confirms active exploitation globally and has added both to its Known Exploited Vulnerabilities catalog.
  |  By Eliane Guindon
Canada has taken a significant step toward strengthening national cyber resilience. With Royal Assent now granted to Bill C-8, the Government of Canada is establishing a new framework for protecting critical cyber systems and securing the country's most essential services.
  |  By Adam Pumphrey
Every SOC analyst has been there. An alert fires. You know what you need to find. Maybe it's all outbound connections from a specific host that spiked overnight. Maybe it's every DNS query over 100 characters from a subnet you're watching. You know the question. What you don't know is the exact query syntax you need to ask it. So you open the documentation. You search for field names. You try a query, get it wrong, adjust, and try again. Minutes pass.
  |  By Josh Porto
Post-Quantum Cryptography (PQC) is the security equivalent of showing up at the airport and discovering TSA changed the rules overnight again: Laptops out, laptops in, shoes off, shoes on, and declare your shampoo like it’s contraband uranium. You can argue with the signage, but the plane is still leaving, and compliance is not optional. The good news is you don’t need a physics degree, a quantum computer, or a wellness crystal to deal with it.
Recent cyberattacks against U.S. water and wastewater systems have put some familiar operational technology (OT) security problems back in the headlines. Federal agencies have warned about malicious actors targeting internet-facing programmable logic controllers (PLCs), changing device configurations, and disrupting operations at utilities across multiple states.
  |  By Tim Chiu
Every breach that lands a CISO in front of the board has a common final act: Data leaving the building. Attackers don't get paid for breaking in. They get paid for what they take out. And by the time stolen data appears on an extortion site or in a regulator's inbox, the window to stop the damage has already closed. That is what makes exfiltration so dangerous. It rarely looks like an emergency.
  |  By Tim Chiu
AI adoption is outpacing enterprise control. The 2026 Verizon DBIR found that 45% of employees regularly use AI on corporate devices, and 67% of those users access AI through non-corporate accounts. Cyberhaven Labs reports that 39.7% of data sent to AI tools is sensitive, while endpoint AI app adoption grew 509% year over year.
  |  By Cynthia Gonzalez
With Corelight Sensor v29.2, generally available September 16, 2026, your team gains the ability to behaviorally detect and disrupt multi-stage intrusions, govern AI usage across your network without decryption, and deploy sensors in minutes instead of hours. This post covers what’s new and how it accelerates your security operations.
  |  By Vince Stoffer, Field CTO
Post-quantum cryptography (PQC), and the many ways it intersects with IT and cybersecurity, is becoming increasingly important to organizations of every size. While it seemed like an esoteric concept a few years ago, relegated to cryptographers' conference talks, it’s now something that comes up in many of our customer conversations.
  |  By Corelight
What happens when you ask a generic SIEM AI assistant and a Corelight-powered threat hunter agent the exact same question about a suspicious IP? The difference is not the model. It is the investigation expertise. In this demo, we walk through a side-by-side comparison using Elastic's agent builder. A default AI assistant returns a surface-level summary. An agent built with the Corelight Agent Builder Library identifies lateral movement, flags potential ransomware and data exfiltration, surfaces IDS alerts, maps involved hosts, and recommends next steps.
  |  By Corelight
In this episode, host Richard Bejtlich sits down with Christian Kreibich, Zeek's technical lead, to unpack the upcoming Zeek 9 release and what it means for practitioners. Christian explains how the project structures its three-releases-a-year cadence and how the team has spent recent cycles modernizing Zeek—including the shift to ZeroMQ for cluster messaging and new systemd-based cluster orchestration. A major thread is security.
  |  By Corelight
Developing the full picture of an incident is essential for SOC teams responding to complex threats. A financial firm faced this challenge when attackers created legitimate accounts within their Google Workspace environment. While native alerts flagged the activity, investigators needed deeper context to determine scope and exposure. With Corelight, the team gained the network evidence and chronological activity timeline needed to scope the incident and restore full visibility.
  |  By Corelight
In this episode, host Richard Bejtlich sits down with Steve Smoot, Chief Technical Officer at Corelight, to explore how AI is reshaping the daily work of engineers and defenders alike. Steve traces his path from early employee to CTO and explains why the flexibility of Open NDR—where a simple ten-line Zeek or Spicy script can solve a customer's edge case without a full product release—remains a core advantage. The conversation digs into practical realities of working with large language models.
  |  By Corelight
Corelight Senior Security Engineer Jordan Hair joins Richard Bejtlich to break down how defense teams can leverage agentic AI harnesses to transform traditional security operations. By wrapping deterministic code around large language models, Hare created automated agents for alert triage, threat hunting, and detection engineering that shrink routine investigations from 45 minutes down to seconds.
  |  By Corelight
Corelight’s James Pope joins Dark Reading’s Joan Goodchild at Black Hat USA to share lessons from more than a decade defending one of cybersecurity’s most unique network environments: the Black Hat Network Operations Center (NOC). As SOC lead for the Black Hat NOC since 2014, James helps oversee more than 100 analysts, threat hunters, and partners tasked with distinguishing legitimate security research from real attacks across a network built from scratch for the conference.
  |  By Corelight
Cyber defense in the age of Mythos Advanced AI has fundamentally shifted the security landscape, shrinking the window for vulnerability exploitation from weeks to hours. When standard patching workflows can't keep pace, your network becomes your most critical line of defense. In this video, we explore how Corelight transforms network traffic into actionable security insights to power your SOC. The best data drives the best defense. Discover how to improve your SOC outcomes by up to 300% over legacy data.
  |  By Corelight
Richard Bejtlich joins Vince Stoffer to unpack the ideas behind his new book on network detection and response, starting with a practical distinction: NSM is a strategy, while NDR is a product. The conversation explores what teams should expect from network data, how alerts and threat hunting work together, why prevention eventually fails, and how AI can help practitioners investigate unfamiliar logs, alerts, and artifacts without replacing human judgment.
  |  By Corelight
In this episode, host Richard Bejtlich sits down with Corelight Co-founder and Chief Strategy Officer Greg Bell to unpack groundbreaking research that quantifies exactly how data quality impacts AI-driven security automation. Moving past qualitative industry hype, Greg shares hard evidence from an empirical experiment pitting leading AI agents against real-world Capture the Flag (CTF) challenges and incident response report writing. The findings reveal a dramatic truth: basic firewall and flow logs place a hard cap on inference, throttling an LLM's capacity for deep insight.
  |  By Corelight
In this episode, host Richard Bejtlich sits down with Corelight Senior Sales Engineers Adam Donadeo and Nico Roosenboom to unpack their firsthand experiences at Locked Shields, the world’s largest international live-fire cyber defense exercise. The conversation dives deep into the chaotic, real-world friction of defending a massive virtualized network alongside 4,000 global experts against aggressive red team waves.

Corelight gives you the high ground—a commanding view of your network that lets you outsmart and outlast adversaries.

From the Acropolis to the edge of space, defenders have sought the high ground in order to see farther and turn back attacks. Corelight delivers a commanding view of your network so you can outsmart and outlast adversaries. We capture, interpret, and connect the data that means everything to defenders.

Corelight gives apex defenders the information and tools they need to successfully detect and respond to threats. Corelight is built on Zeek, an open-source, global standard technology. Zeek provides rich, structured, security-relevant data to your entire SOC, making everyone from Tier 1 analysts to seasoned threat hunters far more effective.

The Open NDR Platform:

  • Suricata: Suricata generates alerts that we embed directly into Zeek logs, putting every detection into context to save time, cut alert backlogs, and improve analytics.
  • Zeek: The Zeek open source network security monitor generates lightweight metadata and detections to enable threat hunting and speed incident response.
  • Smart PCAP: Smart PCAP links logs, extracted files, and insights with just the packets you need, to reduce storage costs while expanding retention times by a factor of 10.

Faster investigations, more effective threat hunts with the world's best network evidence.