# Cyber Company Profiles: Corelight

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-11
Analyzed 2026-09-04
Canonical: https://cybercompanyprofiles.com/companies/corelight
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Corelight, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [corelight.com](https://corelight.com)
- Profile: https://cybercompanyprofiles.com/companies/corelight
- Type: Network Security, Detection Response, Security Operations, Threat Intelligence
- Also known as: Corelight, Inc.
- Market readiness: Established (27/40)
- Defensibility: Contested (14/21)
- Founded: 2013
- Funding: $309.2M total
- Last updated: 2026-09-04

## Executive Summary

Corelight sells network detection and response to security operations teams. Its evidence engine is Zeek, an open-source project its co-founder created at a national laboratory and the company still maintains, and the open-source Suricata runs beside it for intrusion detection. Anyone can run that open-source layer. What a customer pays for is appliances parsing traffic above 100 gigabits per second, the console that manages them, Corelight's own machine-learning and behavioral detections, and an investigation service that records its reasoning. The traction record outside Corelight's own pages is short: Network World names Carrefour and Grand Canyon Education as customers, and TechTarget places the tools in the Black Hat conference network.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Corelight sells the Open NDR Platform, which turns network and cloud traffic into structured evidence for security operations teams and layers AI-assisted detection and triage on top of it. | [\[f1\]](#company-detail-sources) |
| Founded | 2013 | [\[f2\]](#company-detail-sources) |
| HQ | San Francisco, California, United States | [\[f2\]](#company-detail-sources) |
| Funding | $309.2M total | [\[f2\]](#company-detail-sources) |
| Latest funding | Series E, 150M USD, closed April 2024 | [\[f2\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Corelight Sensors | Passive traffic monitors sold as hardware appliances, virtual machines, cloud instances, flow collectors, and software, which parse network activity into structured logs. |
| Corelight Investigator | The cloud-delivered side of the platform, where detections are correlated into entity-level cases and agentic playbooks run triage and one-click containment. |
| Corelight Fleet Manager | Central console for configuring, updating, and monitoring a deployed sensor estate, including Zeek packages, Suricata rulesets, and YARA rules. |
| Smart PCAP | Subscription module that keeps only the packets a rule selects, with rules set on address, port, protocol, or Zeek and Suricata events. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f3\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Networks | ✓ |  | ✓ | ✓ |  |
| Devices | ✓ |  |  |  |  |

Corelight Sensors passively classify every device and AI service that communicates on the network, including operational-technology and unmanaged endpoints that conventional scanners can miss. These capabilities are mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (27/40)**

Analyzed 2026-09-04. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | Corelight names the buyer as the security operations team and the pain as slow attacks, alert volume and tool sprawl, and Network World describes the platform in its own words as aiming at alert overload and tool sprawl. The figures attached to that pain, a 98 percent alert reduction and triage ten times faster, sit on Corelight's own pages, and no reviewed source measures the problem independently. \[[s8](#profile-analysis-sources), [s1](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | Corelight publishes per-model appliance specifications down to traffic analysis speeds, monitoring interfaces, power draw and operational mode, and documents its detection, triage and packet-capture modules separately. The engine underneath is Zeek, whose design was published at the 7th USENIX Security Symposium in 1998 and whose code is open to inspection, which is an external validation point beyond the vendor's own pages. \[[s24](#profile-analysis-sources), [s15](#profile-analysis-sources), [s17](#profile-analysis-sources), [s10](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |
| Market Timing | 3/5 | Network detection and response is a settled category that Corelight ships into continuously, adding passive asset classification and network performance monitoring in June 2026. The Leader placement in Gartner's network detection quadrant reaches the record only through Corelight's own announcement, and the independent sources carry category framing and investor interest rather than buyers searching, so the demand signal stays indirect. \[[s14](#profile-analysis-sources), [s8](#profile-analysis-sources), [s22](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | Vern Paxson created the open-source project now called Zeek and published its design at USENIX Security in 1998. Network World attributes that work to him alongside co-founders Robin Sommer and Seth Hall. Network World also records chief executive Brian Dye arriving from product leadership at McAfee and security leadership at Symantec. That is verifiable in-domain experience and one prior build. The founders' awards appear only on the company's own leadership page. The reviewed record does not reach the plural builds or the independent publication standing the next rung asks for. \[[s10](#profile-analysis-sources), [s8](#profile-analysis-sources), [s4](#profile-analysis-sources), [s7](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | Network World names Carrefour and Grand Canyon Education as customers, and TechTarget records Cisco analyzing data gathered from Corelight's network visibility tools inside the Black Hat conference network, which is an outside observer describing the product in use. Integrations reach Splunk, CrowdStrike, Microsoft Defender and other platforms, and both Cisco Investments and the CrowdStrike Falcon Fund joined the 2024 round, but no reviewed independent source reports revenue or a customer count. \[[s8](#profile-analysis-sources), [s20](#profile-analysis-sources), [s16](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | Corelight has raised $309.2 million in total with a $150 million Series E in April 2024, proportional to a company selling appliances, software and a cloud service into large enterprises and government agencies. Shipping is visible across sensor releases, an agentic triage launch and a federal marketplace listing, and no reviewed independent source reports revenue, margin or company-wide growth, so efficiency itself stays unconfirmed. \[[s8](#profile-analysis-sources), [s13](#profile-analysis-sources), [s14](#profile-analysis-sources), [s18](#profile-analysis-sources), [s15](#profile-analysis-sources), [s21](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Three independent publications place Corelight in the network detection and response category, and Network World sets it against ExtraHop and Vectra directly and against Cisco, CrowdStrike and Microsoft indirectly. The Leader placement in Gartner's inaugural network detection quadrant reaches the record only through Corelight's own announcement, which holds the score below the independently confirmed rung. \[[s8](#profile-analysis-sources), [s13](#profile-analysis-sources), [s20](#profile-analysis-sources), [s22](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | A deployed sensor estate, tuned rulesets and the wiring into a customer's log platform create real friction, and Corelight's evidence feeds platforms such as Splunk and CrowdStrike rather than competing with them head on. The engines are open source and two large adjacent platform vendors invested in the 2024 round, and the reviewed record shows no structural moat that bundling could not eventually reach. \[[s1](#profile-analysis-sources), [s16](#profile-analysis-sources), [s7](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |

### Business Risks

- Zeek and Suricata, the engines under the platform, are open source, so a rival can ship the same foundation and compete on the appliances, management console, detection content and proprietary modules Corelight builds on top.
- Cisco Investments and the CrowdStrike Falcon Fund both backed the 2024 round, and Network World lists both parent companies among the larger vendors selling something similar, so a partner in one account can be the competitor in the next.
- The federal entry is an In Process listing on the FedRAMP Marketplace at Class C rather than a completed authorization, so an agency that requires an authorized cloud service has to wait for the process to finish.
- No reviewed independent source reports Corelight revenue, customer count or growth, so a buyer weighing the company's staying power is working from the company's own account.
- Corelight sensors sit out of band and export Zeek-format evidence into a customer's own platform, so a rival that emits the same evidence can compete for the sensor layer without displacing the tools around it.

### Problem & Market

Corelight sells to the security operations team that already runs endpoint and log tooling and still cannot see what crossed the network. Network World describes the platform in its own words as aiming at network detection weak spots including alert overload and tool sprawl, and reports Corelight's own account of three failures it targets: attacks that move slowly and quietly, alert volume analysts cannot work through, and a stack of separate monitoring products.

The scale of that pain is asserted rather than measured. Corelight leads with a 98 percent reduction in alerts and triage ten times faster, and both figures sit on its own pages. No reviewed source outside the company sizes the budget moving toward network detection or counts the teams that report the problem.

The category itself is not in question. Network World places Corelight against ExtraHop and Vectra as direct rivals and against Cisco, CrowdStrike and Microsoft as larger companies selling something similar. \[[s8](#profile-analysis-sources), [s1](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Product Capabilities

The sensor is the product a customer installs. Corelight Sensors passively analyze traffic and log network activity, and ship as hardware appliances, virtual machines, cloud instances, flow collectors and software. The appliance line is documented model by model, down to traffic analysis speeds, monitoring interfaces, power draw and an operational mode described as out of band, fed by tap, span or packet broker. SiliconANGLE reports appliances that scan more than 100 gigabits per second.

The software layers sit on top of that evidence. Corelight Investigator is the cloud service that correlates detections into cases, maps them across more than 100 MITRE ATT&CK techniques, runs Agentic Triage through expert-written playbooks, and lets an analyst isolate a host from a validated case. Corelight Fleet Manager configures and updates the sensor estate, pushing Zeek packages, Suricata rulesets and YARA rules from one console. Smart PCAP is a subscription module that keeps only the packets a rule selects, with rules defined on address, port, protocol or Zeek and Suricata events, which is how the company extends how far back an investigator can pull packet evidence.

The June 2026 release widened what the same sensor produces. Help Net Security records passive asset classification of every device the moment it communicates, naming industrial control, operational technology, unmanaged endpoints and language-model endpoints, plus native network performance monitoring, both drawn from traffic the sensor already collects. \[[s24](#profile-analysis-sources), [s15](#profile-analysis-sources), [s16](#profile-analysis-sources), [s17](#profile-analysis-sources), [s13](#profile-analysis-sources), [s14](#profile-analysis-sources)\]

### Competitive Positioning

Corelight competes on the same ground as the network detection specialists and lives alongside the platforms. Network World names ExtraHop and Vectra as direct rivals, and Cisco, CrowdStrike and Microsoft as larger companies selling something similar. The same article records that Cisco Investments and the CrowdStrike Falcon Fund both put money into the 2024 round, so two of those larger companies hold positions in the vendor they overlap with.

The differentiation Corelight argues is openness. Its engines are public projects, its evidence is exported in a format other tools consume, and its federal announcement puts the argument plainly: security teams keep control of their data, write their own detections and avoid vendor lock-in. That argument makes Corelight easier to place beside Splunk, CrowdStrike or Microsoft Defender than a product that wants to own the console.

The same openness lowers part of what a rival has to reproduce. Zeek and Suricata are available to anyone, so a competitor starts from the same public foundation and has to match the appliance line, the fleet console, the detection content and the work Corelight says it built itself for encrypted collections and packet capture. Corelight's own account claims the steward position on Zeek, which is standing in a community rather than an asset a rival is barred from using. \[[s8](#profile-analysis-sources), [s7](#profile-analysis-sources), [s21](#profile-analysis-sources), [s3](#profile-analysis-sources), [s1](#profile-analysis-sources), [s16](#profile-analysis-sources)\]

### Go-to-Market & Traction

Two customer names reach the record through an outside publication. Network World names Carrefour and Grand Canyon Education, and Corelight's homepage adds anonymized case studies from an energy company, a mortgage lender and a United States government agency.

The strongest independent traction signal is not a customer at all. TechTarget reports that Cisco provided domain-name and file analysis of data gathered from Corelight's network visibility tools at the Black Hat conference network, and that a Corelight senior director served as its security operations lead. Network World separately carries Corelight's claim that services teams at CrowdStrike and Mandiant use the product, which is the company's account rather than an outside one.

The product is built to interoperate with the platforms a buyer already owns. The homepage documents integration with Splunk Enterprise Security and Splunk SOAR, and Fleet Manager connects to CrowdStrike, Microsoft Defender, SentinelOne, Tenable and Axonius. What the reviewed record does not carry is any independent figure for revenue, customer count or growth, so the size of the business is only what Corelight states it is. \[[s8](#profile-analysis-sources), [s20](#profile-analysis-sources), [s7](#profile-analysis-sources), [s1](#profile-analysis-sources), [s16](#profile-analysis-sources)\]

### Team & Credibility

The founding story is unusually checkable because part of it is published research. Vern Paxson created the open-source project now called Zeek while at Lawrence Berkeley National Laboratory, and presented the original system's design at the 7th USENIX Security Symposium in 1998. Network World attributes the open-source work to him with co-founders Robin Sommer and Seth Hall, and Corelight lists Paxson as chief scientist and Sommer as an advisor and co-founder emeritus.

Corelight has a chief executive who is not a founder, and its co-founders hold the strategy and research roles. Network World records that chief executive Brian Dye came from product leadership at McAfee and information security leadership at Symantec. Corelight's own leadership page adds a federal chief technology officer who spent more than 33 years in the Department of Defense, a research lead from Palo Alto Networks, and a development chief from Exabeam.

What the independent record supports is a verifiable build and a publication, plus a chief executive with two large-vendor product histories. The honours the company lists for its founders, including professional society awards, appear on its own pages and nowhere else in the reviewed sources. \[[s10](#profile-analysis-sources), [s8](#profile-analysis-sources), [s4](#profile-analysis-sources), [s3](#profile-analysis-sources), [s13](#profile-analysis-sources)\]

### Trust Readiness

Corelight runs a published trust centre, and it routes the artifacts a buyer wants through a portal rather than a page. The site states that its offerings are independently audited and certified, and directs a reader to a self-service portal to view certifications and request audit reports. No certificate or report is named on the trust centre's public pages.

The federal position is a step in progress rather than a completed one. Corelight announced in June 2026 that the Open NDR Platform, including Investigator and Hosted Fleet Manager, is listed on the FedRAMP Marketplace as In Process at the Class C moderate level, which the announcement itself describes as active progress through the process.

Deployment choice is where the company puts its trust argument. Sensors can run on premises or air-gapped and feed evidence into a customer's own log platform, the cloud service is offered as an alternative rather than a requirement, and the federal announcement frames custom detections and stack integration as the customer keeping control of its data. \[[s5](#profile-analysis-sources), [s21](#profile-analysis-sources), [s25](#profile-analysis-sources), [s18](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| ExtraHop | competes with | Network World names it a direct rival in network detection and response. |
| Vectra AI | competes with | Network World names it a direct rival in network detection and response. |
| Cisco | competes with | Network World lists it among the larger companies selling something similar, and its investment arm joined Corelight's 2024 round. |
| CrowdStrike | competes with | Network World lists it among the larger companies selling something similar, and its venture fund joined Corelight's 2024 round. |
| Microsoft | competes with | Network World lists it among the larger companies selling something similar, and Fleet Manager connects to its endpoint product. |
| Splunk | adjacent | Adjacent because Corelight is designed to feed evidence into Splunk, allowing the products to sit in the same stack. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (14/21)**

Band guidance: reinforce or reposition. Analyzed 2026-09-04. Scope: whole company.

Zeek and Suricata, the engines at the base of Corelight's platform, are open source, so a customer with enough engineers can run them without paying. What Corelight sells on top is its own work: appliances that parse traffic above 100 gigabits per second, machine-learning and behavioral detections, technologies it built for encrypted collections and packet capture, and an auditable investigation service. A funded rival can build each of those, and the reviewed record names no dataset Corelight keeps to itself. A customer stays through ordinary friction: installed sensors, tuned rulesets, and the wiring into whatever platform consumes the logs. The reviewed sources do not size what leaving would cost, so that friction is a head start rather than a durable lead.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Corelight delivers appliances and software that the customer's own team operates and owns the outcomes of, with professional services and training offered alongside the platform. The reviewed record documents no detection service Corelight runs on a customer's behalf and no outcome commitment the company accepts. \[[s24](#deep-dive-sources), [s1](#deep-dive-sources), [s15](#deep-dive-sources), [s17](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Real friction accumulates: an installed sensor fleet, configuration templates and rulesets pushed from Fleet Manager, and the wiring into whatever log platform consumes the evidence. The sensors watch a copy of the traffic rather than carrying it, and the evidence is exported into a customer's own SIEM, data lake or XDR platform, and the cited record does not size the migration a departure would require. \[[s16](#deep-dive-sources), [s24](#deep-dive-sources), [s21](#deep-dive-sources), [s25](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | The trust centre states that offerings are independently audited and certified, and routes certificates and audit reports to a self-service portal, which is entry cost a funded competitor reaches through ordinary enterprise-market preparation. The FedRAMP entry is an In Process marketplace listing at Class C moderate rather than an authorization, so it is not a credential a replacement must already hold. \[[s5](#deep-dive-sources), [s21](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Parsing live traffic into protocol logs above 100 gigabits per second, running signature, behavioural and machine-learning detection over the result, and correlating it into entity-level cases is real-time systems work rather than a feature release. The engine's design was published as a conference paper in 1998 and has been developed continuously since. \[[s13](#deep-dive-sources), [s2](#deep-dive-sources), [s24](#deep-dive-sources), [s10](#deep-dive-sources), [s7](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | The evidenced buyers are large enterprises and government agencies. Corelight states that it serves large enterprises and government agencies in more than fifteen countries, Network World names Carrefour and Grand Canyon Education, and the federal announcement is addressed to United States agencies with a federal chief technology officer attached to it. \[[s3](#deep-dive-sources), [s8](#deep-dive-sources), [s21](#deep-dive-sources)\] |
| Layer | 2/3 | Corelight integrates with Splunk, CrowdStrike and Microsoft Defender, and Corelight Investigator adds a console of its own where analysts investigate and respond. The sensors are out of band, so removing them stops the evidence without stopping production traffic, and the reviewed record shows no third-party application built to depend on the platform. \[[s1](#deep-dive-sources), [s16](#deep-dive-sources), [s24](#deep-dive-sources), [s15](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 2/3 | Zeek and Suricata, the engines the platform is built on, are open source, so the core is reproducible. Corelight's about page states it created its own proprietary technologies for VPN, encrypted collections and packet capture. That is engineering IP rather than an accumulating corpus. The reviewed sources name no non-public dataset and no cross-customer data the company retains. The advantage is replicable with time and effort. \[[s3](#deep-dive-sources), [s23](#deep-dive-sources), [s7](#deep-dive-sources)\] |

### Strategic Market Segmentation

Corelight sells to organizations large enough to run a security operations team and to care what crossed the network. The company states that it serves large enterprises and government agencies in more than fifteen countries, and it maintains dedicated pages for energy, federal, financial services, healthcare and state, local and education buyers.

The independent record points at the same tier. Network World names Carrefour and Grand Canyon Education, and TechTarget places the tools inside the Black Hat conference network, an environment run by security practitioners. Corelight's own case studies add an energy company, a major mortgage lender and a United States government agency, most of them unnamed.

Nothing in the reviewed record points at the small end of the market. The reviewed pages carry no self-service tier and no published price, and the smallest published appliance, the AP 220, is described as suited to branch offices. \[[s3](#deep-dive-sources), [s8](#deep-dive-sources), [s20](#deep-dive-sources), [s24](#deep-dive-sources), [s6](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The differentiating engineering is the sensor rather than the analytics. Corelight Sensors passively analyze traffic and log network activity as hardware appliances, virtual machines, cloud instances, flow collectors and software, and the appliance line is published model by model with traffic analysis speeds, monitoring interfaces and an out-of-band operational mode fed by tap, span or packet broker. SiliconANGLE reports appliances scanning more than 100 gigabits per second.

The detection story is deliberately plural rather than single-model. Corelight describes fusing machine learning, behavioural analytics, curated signatures and threat intelligence into risk-ranked alerts, and Investigator maps detections across more than 100 MITRE ATT&CK techniques. The AI layer is built around auditability: Agentic Triage runs expert-written playbooks so the reasoning behind a verdict can be read back, and the federal announcement frames custom detections and open integration as the customer keeping control.

The June 2026 release turned the same traffic into an inventory. Help Net Security records passive classification of every device the moment it communicates, including industrial control, operational technology, unmanaged endpoints and language-model endpoints, alongside native network performance monitoring, all from data the sensor already collects.

The reviewed record names no private dataset under any of it. Zeek and Suricata are open source, the Corelight Labs mission is stated as producing monitoring content, and the company's own claim to proprietary work names technologies it built for encrypted collections and packet capture rather than a corpus it has accumulated. \[[s24](#deep-dive-sources), [s2](#deep-dive-sources), [s15](#deep-dive-sources), [s13](#deep-dive-sources), [s14](#deep-dive-sources), [s3](#deep-dive-sources), [s23](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

The motion is enterprise sales with a channel and a partner ecosystem behind it. The site carries a partner programme with deal registration, a channel-partner path and a technology partner directory, and the reviewed pages show no self-service path: the contact page offers pricing or a quote and a demo request.

The product is built to interoperate with the platforms the buyer already owns. Corelight documents native integration with Splunk Enterprise Security and Splunk SOAR, and Fleet Manager connects to CrowdStrike, Microsoft Defender, SentinelOne, Tenable and Axonius. Cisco Investments and the CrowdStrike Falcon Fund both invested in the 2024 round, so two vendors in that ecosystem also hold positions in Corelight.

Proof of the motion working is thinner than the motion itself. Two customers are named by an outside publication, Corelight's own claim that services teams at CrowdStrike and Mandiant use the product reaches the record through Network World as the company's account, and no independent source in the reviewed set reports revenue, a customer count or a growth rate. \[[s1](#deep-dive-sources), [s6](#deep-dive-sources), [s16](#deep-dive-sources), [s7](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Pricing Model

Corelight publishes no price. The contact page invites a buyer to ask for pricing or a quote, and no page in the reviewed set carries a rate card, a tier list or a starting figure.

The packaging is legible even where the price is not. The platform separates into sensor models differentiated by traffic-analysis capacity, with the appliance line published by traffic analysis speed. Smart PCAP is described as a subscription module purchased with Corelight Sensors, and Investigator is the software-as-a-service detection and investigation layer that runs on the sensors' evidence.

Deployment choice does the work a price list usually does. A customer can buy sensors only and feed evidence to its own log platform, buy the cloud service, or run a hybrid of the two, which lets the same product line address an air-gapped agency and a cloud-first enterprise without a separate offering. \[[s6](#deep-dive-sources), [s24](#deep-dive-sources), [s17](#deep-dive-sources), [s25](#deep-dive-sources)\]

### Product Delivery & Operations

A customer can run sensors on its own premises or take the cloud-delivered components, and its security team owns the decisions either way. Corelight offers professional services and training alongside the platform, and the reviewed record documents no managed detection service Corelight runs on a customer's behalf and no outcome it accepts accountability for.

Fleet operations are where the product invests. Fleet Manager configures, updates and monitors deployed sensors from one console, pushing Zeek packages, Suricata rulesets, Smart PCAP policies and YARA rules, with role-based access, health dashboards and an audit trail of configuration changes. Corelight claims quick-start templates that cut policy creation time by up to 80 percent, which is the company's own figure.

Investigator is where day-to-day analyst work happens. It consolidates the highest-priority entities every 24 hours, investigates the last seven days of host activity, and lets an analyst isolate a host or push a firewall policy change from a validated case, which keeps the response step inside the same interface as the evidence. \[[s1](#deep-dive-sources), [s16](#deep-dive-sources), [s15](#deep-dive-sources), [s17](#deep-dive-sources), [s25](#deep-dive-sources)\]

### Earning Customers' Trust

Corelight publishes a trust centre and gates the artifacts behind it. The page states that its offerings are independently audited and certified, and directs a reader to a self-service portal to view certifications and request audit reports. No certificate or report is named on the trust centre's public pages.

The federal credential is in progress. Corelight announced in June 2026 that the Open NDR Platform, including Investigator and Hosted Fleet Manager, is listed on the FedRAMP Marketplace as In Process at the Class C moderate level, and the announcement itself describes that as active progress through the process rather than a completed authorization.

Data control is the trust argument the company actually leads with. Sensors can run on premises or air-gapped and export evidence into a customer's own platform, the announcement frames the openness as customers keeping control of their data and avoiding vendor lock-in, and the cloud service is an option rather than a precondition. \[[s5](#deep-dive-sources), [s21](#deep-dive-sources), [s25](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Corelight supplies evidence to other consoles and runs one of its own. Its evidence lands in Splunk Enterprise Security and Splunk SOAR through native integration, and Fleet Manager's connector framework reaches CrowdStrike, Microsoft Defender, SentinelOne, Tenable and Axonius, ingesting threat intelligence over STIX and TAXII 2.1 or any HTTP endpoint.

The open-source foundation is the ecosystem's other half. Zeek and Suricata are public projects and Corelight describes itself as Zeek's steward. The design of the original system was published at the 7th USENIX Security Symposium in 1998. Corelight says its unified, standard Zeek log format simplifies investigations and integrations with the tools a customer already runs.

That position cuts both ways. TechTarget records Cisco performing domain-name and file analysis on data gathered from Corelight's tools at the Black Hat conference network, which shows the interoperability working in public. It also puts a larger platform above Corelight's evidence, which is the screen Corelight Investigator competes for. \[[s1](#deep-dive-sources), [s16](#deep-dive-sources), [s3](#deep-dive-sources), [s10](#deep-dive-sources), [s20](#deep-dive-sources), [s25](#deep-dive-sources), [s13](#deep-dive-sources)\]

### Team & Execution Capability

The founding claim rests on published research rather than on the company's own account alone. Vern Paxson created the open-source project now called Zeek while at Lawrence Berkeley National Laboratory, and presented the original system's design at the 7th USENIX Security Symposium in 1998. Network World attributes the open-source work to him with co-founders Robin Sommer and Seth Hall, and Corelight lists Paxson as chief scientist and Sommer as an advisor and co-founder emeritus.

Several operating leaders came from outside. Network World records that chief executive Brian Dye held product leadership at McAfee and information security leadership at Symantec. Corelight's leadership page adds a federal chief technology officer with more than 33 years in the Department of Defense, a Corelight Labs lead from Palo Alto Networks, and a development chief from Exabeam, and its newsroom shows a chief customer officer appointed in July 2026.

Research capacity sits in Corelight Labs, whose stated mission is content that enables detailed monitoring of enterprise network activity, staffed with security researchers and data scientists. The honours the company lists for its founders, including professional society awards, appear on its own pages and are not corroborated elsewhere in the reviewed sources. \[[s10](#deep-dive-sources), [s8](#deep-dive-sources), [s4](#deep-dive-sources), [s18](#deep-dive-sources), [s23](#deep-dive-sources), [s3](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Corelight: Open NDR Platform overview](https://corelight.com/platform/) | official | 2026-09-04 |
| f2 | [Network World: Corelight boosts AI-driven network detection and response](https://www.networkworld.com/article/3479557/corelight-boosts-ai-driven-network-detection-and-response.html) | press | 2026-09-04 |
| f3 | [Help Net Security: Corelight enhances Open NDR to detect AI-driven threats and unknown assets](https://www.helpnetsecurity.com/2026/06/17/corelight-open-ndr-platform-expansion/) | press | 2026-09-04 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Corelight homepage](https://corelight.com/) | official | 2026-09-04 |
| s2 | [Corelight: Open NDR Platform overview](https://corelight.com/platform/) | official | 2026-09-04 |
| s3 | [Corelight: About us](https://corelight.com/company/about-corelight/) | official | 2026-09-04 |
| s4 | [Corelight: Leadership](https://corelight.com/company/leadership) | official | 2026-09-04 |
| s5 | [Corelight Trust Center, probe of the published compliance surface](https://corelight.com/trust-and-compliance) | official | 2026-09-04 |
| s6 | [Corelight: Contact and office locations](https://corelight.com/contact) | official | 2026-09-04 |
| s7 | [Network World: Cisco-backed startup Corelight raises $150M to expand network security services](https://www.networkworld.com/article/2097140/cisco-backed-startup-corelight-raises-150m-to-expand-network-security-services.html) | press | 2026-09-04 |
| s8 | [Network World: Corelight boosts AI-driven network detection and response](https://www.networkworld.com/article/3479557/corelight-boosts-ai-driven-network-detection-and-response.html) | press | 2026-09-04 |
| s10 | [USENIX: Bro, A System for Detecting Network Intruders in Real-Time, conference paper record](https://www.usenix.org/conference/7th-usenix-security-symposium/bro-system-detecting-network-intruders-real-time) | research | 2026-09-04 |
| s11 | [SEC EDGAR: TriplePoint Venture Growth BDC Corp. Form 10-Q for the quarter ended 2026-06-30](https://www.sec.gov/Archives/edgar/data/1580345/000158034526000025/tpvg-20260630.htm) | regulatory | 2026-09-04 |
| s13 | [SiliconANGLE: Network security startup Corelight reels in $150M](https://siliconangle.com/2024/04/30/network-security-startup-corelight-reels-150m/) | press | 2026-09-04 |
| s14 | [Help Net Security: Corelight enhances Open NDR to detect AI-driven threats and unknown assets](https://www.helpnetsecurity.com/2026/06/17/corelight-open-ndr-platform-expansion/) | press | 2026-09-04 |
| s15 | [Corelight: Investigator component page](https://corelight.com/platform/investigator) | official | 2026-09-04 |
| s16 | [Corelight: Fleet Manager component page](https://corelight.com/platform/fleet-manager) | official | 2026-09-04 |
| s17 | [Corelight: Smart PCAP module page](https://corelight.com/platform/smart-pcap) | official | 2026-09-04 |
| s18 | [Corelight: Newsroom press-release index](https://corelight.com/company/newsroom?filter=press-releases) | official | 2026-09-04 |
| s20 | [TechTarget: Behind the scenes at Black Hat's network operations center](https://www.techtarget.com/cybersecurity/news/366649216/Behind-the-scenes-at-Black-Hats-network-operations-center) | press | 2026-09-04 |
| s21 | [Corelight announcement: FedRAMP In Process listing at Class C (Moderate)](https://corelight.com/company/newsroom/press-releases/2026-06-09-corelight-achieves-fedramp-in-process-certification-advancing-network-detection-and-response-for-federal-government-agencies) | official | 2026-09-04 |
| s22 | [Corelight announcement: Leader placement in the inaugural Gartner Magic Quadrant for Network Detection and Response](https://corelight.com/company/newsroom/press-releases/2025-05-29-corelight-recognized-as-a-leader-in-the-inaugural-magic-quadrant-tm-for-network-detection-and-response) | official | 2026-09-04 |
| s23 | [Corelight: Corelight Labs mission and team](https://corelight.com/solutions/corelight-labs/mission-team) | official | 2026-09-04 |
| s24 | [Corelight: Sensors component page with per-model specifications](https://corelight.com/platform/sensors) | official | 2026-09-04 |
| s25 | [Corelight: Deployment options page](https://corelight.com/platform/deployment-options) | official | 2026-09-04 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Corelight homepage](https://corelight.com/) | official | 2026-09-04 |
| s2 | [Corelight: Open NDR Platform overview](https://corelight.com/platform/) | official | 2026-09-04 |
| s3 | [Corelight: About us](https://corelight.com/company/about-corelight/) | official | 2026-09-04 |
| s4 | [Corelight: Leadership](https://corelight.com/company/leadership) | official | 2026-09-04 |
| s5 | [Corelight Trust Center, probe of the published compliance surface](https://corelight.com/trust-and-compliance) | official | 2026-09-04 |
| s6 | [Corelight: Contact and office locations](https://corelight.com/contact) | official | 2026-09-04 |
| s7 | [Network World: Cisco-backed startup Corelight raises $150M to expand network security services](https://www.networkworld.com/article/2097140/cisco-backed-startup-corelight-raises-150m-to-expand-network-security-services.html) | press | 2026-09-04 |
| s8 | [Network World: Corelight boosts AI-driven network detection and response](https://www.networkworld.com/article/3479557/corelight-boosts-ai-driven-network-detection-and-response.html) | press | 2026-09-04 |
| s10 | [USENIX: Bro, A System for Detecting Network Intruders in Real-Time, conference paper record](https://www.usenix.org/conference/7th-usenix-security-symposium/bro-system-detecting-network-intruders-real-time) | research | 2026-09-04 |
| s11 | [SEC EDGAR: TriplePoint Venture Growth BDC Corp. Form 10-Q for the quarter ended 2026-06-30](https://www.sec.gov/Archives/edgar/data/1580345/000158034526000025/tpvg-20260630.htm) | regulatory | 2026-09-04 |
| s13 | [SiliconANGLE: Network security startup Corelight reels in $150M](https://siliconangle.com/2024/04/30/network-security-startup-corelight-reels-150m/) | press | 2026-09-04 |
| s14 | [Help Net Security: Corelight enhances Open NDR to detect AI-driven threats and unknown assets](https://www.helpnetsecurity.com/2026/06/17/corelight-open-ndr-platform-expansion/) | press | 2026-09-04 |
| s15 | [Corelight: Investigator component page](https://corelight.com/platform/investigator) | official | 2026-09-04 |
| s16 | [Corelight: Fleet Manager component page](https://corelight.com/platform/fleet-manager) | official | 2026-09-04 |
| s17 | [Corelight: Smart PCAP module page](https://corelight.com/platform/smart-pcap) | official | 2026-09-04 |
| s18 | [Corelight: Newsroom press-release index](https://corelight.com/company/newsroom?filter=press-releases) | official | 2026-09-04 |
| s20 | [TechTarget: Behind the scenes at Black Hat's network operations center](https://www.techtarget.com/cybersecurity/news/366649216/Behind-the-scenes-at-Black-Hats-network-operations-center) | press | 2026-09-04 |
| s21 | [Corelight announcement: FedRAMP In Process listing at Class C (Moderate)](https://corelight.com/company/newsroom/press-releases/2026-06-09-corelight-achieves-fedramp-in-process-certification-advancing-network-detection-and-response-for-federal-government-agencies) | official | 2026-09-04 |
| s22 | [Corelight announcement: Leader placement in the inaugural Gartner Magic Quadrant for Network Detection and Response](https://corelight.com/company/newsroom/press-releases/2025-05-29-corelight-recognized-as-a-leader-in-the-inaugural-magic-quadrant-tm-for-network-detection-and-response) | official | 2026-09-04 |
| s23 | [Corelight: Corelight Labs mission and team](https://corelight.com/solutions/corelight-labs/mission-team) | official | 2026-09-04 |
| s24 | [Corelight: Sensors component page with per-model specifications](https://corelight.com/platform/sensors) | official | 2026-09-04 |
| s25 | [Corelight: Deployment options page](https://corelight.com/platform/deployment-options) | official | 2026-09-04 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
