Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Extending the value of network evidence: Introducing Performance and Asset Visibility

Every packet flowing through a Corelight sensor contains both security-relevant data and performance-relevant data. Until now, Corelight has focused exclusively on extracting security value from network traffic: connection logs, protocol analysis, and threat detections. But the same traffic that reveals lateral movement also reveals TCP latency. The same DNS queries that surface potential C2 channels also reveal resolution timing.

Performance and Asset Visibility Walkthrough

Network security depends on clear visibility across every digital asset. This detailed walkthrough covers Corelight's new Network Performance and Asset Classification logs. You will learn about these two logs, how to configure them, and how to use them during cyber investigations. Network Performance and Asset Visibility logs are available as part of the Sensor v29.1 general availability release to customers with Sensor and Investigator Bundle licenses.

Performance and Asset Visibility Demo

Network security depends on clear visibility across every digital asset. In this brief demo, we will see how Corelight's new Network Performance and Asset Classification logs can be referenced when doing a threat hunt. You will learn about the logs and what information they contain. Network Performance and Asset Visibility logs are available as part of the Sensor v29.1 general availability release to customers with Sensor and Investigator Bundle licenses.

Cato CTRL Insights: Governing Hermes Agent, Security for AI That Learns, Remembers, and Acts

Agentic AI is evolving from assistants that answer questions into systems that can remember, use tools, call APIs, interact with SaaS applications, and improve over time. Hermes Agent, developed by Nous Research, reflects this shift as a self-improving agent that can create skills, persist knowledge, and build context across sessions., reflects this shift as a self-improving agent that can create skills, persist knowledge, and build context across sessions.

VMware ESXi Networking Concepts

For connecting physical servers and computers to a network, you need physical network adapters, switches, and routers. With virtual machines, virtual network concepts are used for communication between the different components of an infrastructure. The proper configuration of ESXi networking on a host is critically important to the configuration of any ESXi environment. Generally, ESXi host networks include storage, vMotion, VM, and management networks.

Corelight Sensor v29.1 release highlights: Network evidence powers network operations

Corelight Sensor v29.1 and Fleet Manager v29.1.1 fundamentally expand what a Corelight Sensor delivers. The release turns existing network evidence into a shared source of truth for SecOps, NetOps, triage, and forensic investigation. Network performance monitoring and asset classification unlock new value from traffic you're already collecting.

Cato CTRL Threat Research: Operation Poisson - Analyzing a Cybercriminal's Entire Operation

Cato CTRL recently analyzed an operator’s command-and-control (C2) server’s entire 33 days operation, including the steps he took to preserve access after the takedown. 339 commands. Four French victims. Between March 30 and May 1, 2026, Cato CTRL studied every command issued by a French-speaking threat actor (“Poisson”) against one French automotive small business and four French individuals.

Let's Talk Security: Leading Healthcare Security Through Constant Change

Healthcare CISOs are navigating one of the most complex security environments. In this conversation, Barry Mainz will be joined by David Finkelstein, CISO, St. Luke’s University Health Network, a seasoned healthcare security leader with experience spanning cyber, operations, and military service, to discuss what it takes to build a modern healthcare cybersecurity program that is resilient today and ready for tomorrow.

9 of the Best Managed IT Services for Focused Cybersecurity Frameworks

Do you know there are between 2,200 and 2,700 impactful cyberattacks every day out of the hundreds of millions of automated attempts? The vast amount of high-potential attacks means that any business or organization needs focused cybersecurity frameworks to proactively deal with the threat. But where do you even begin? Like anything, there are many IT and cybersecurity delivery services for businesses of all sizes, needs, and, of course, budgets.

From CVE Disclosure to Agentic Protection in 45 Minutes. Why it Matters Now.

A CVE lands in the morning. Hours later, attackers are exploiting it in the wild. The patch is not ready, the change window is days away, and the clock is already running. None of this is new. What changed is that vulnerability exploitation is now the most common path into organizations.