NDR / Corelight

Open NDR with Investigator

Corelight combines network evidence with Investigator, a SaaS investigation experience. Its roots in structured network telemetry make it useful for learning how records connect across an investigation. Current product material also describes assisted triage and integrated response, which should be evaluated through their actual evidence and control boundaries.

Commercial network detection and investigationResearch reviewed

What you are evaluating

The evaluated bundle is Corelight network sensors plus Investigator, not the open-source Zeek engine alone. Sensor type, collection licenses, retention, assisted-triage availability and downstream response integrations must be itemized.

A useful evaluation context

Evidence-oriented SOCs evaluating an operated commercial workflow around structured network telemetry.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Network evidence and detection context support entity-oriented investigations.
  • Search and correlation help analysts connect observations across an incident.
  • Current Investigator material describes evidence-linked triage narratives and response through integrated security tools.

Where it fits in the work

  1. Confirm which sensor records reach Investigator and how long they remain searchable.
  2. Start with an entity and follow related network evidence to test the investigation hypothesis.
  3. Compare any generated narrative with its cited observations before approving a downstream action.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

A fabricated investigation narrative says a host moved laterally after an unusual DNS request. Use supplied network records to support or reject each step of that narrative.

Evidence to look for

Deliver a claim-to-evidence table with timestamps and a clearly marked unknown. Treat an AI summary as a hypothesis until the underlying observations support it.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which capabilities come from the licensed sensor versus Investigator?
  2. Can an analyst reproduce an assisted conclusion from retained evidence?
  3. Which external EDR, firewall or identity permissions are required for the proposed response?

Find your next idea.

Tip: press / to open search. Escape closes this window.