What you are evaluating
The evaluated bundle is Corelight network sensors plus Investigator, not the open-source Zeek engine alone. Sensor type, collection licenses, retention, assisted-triage availability and downstream response integrations must be itemized.
A useful evaluation context
Evidence-oriented SOCs evaluating an operated commercial workflow around structured network telemetry.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Network evidence and detection context support entity-oriented investigations.
- Search and correlation help analysts connect observations across an incident.
- Current Investigator material describes evidence-linked triage narratives and response through integrated security tools.
Where it fits in the work
- Confirm which sensor records reach Investigator and how long they remain searchable.
- Start with an entity and follow related network evidence to test the investigation hypothesis.
- Compare any generated narrative with its cited observations before approving a downstream action.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A fabricated investigation narrative says a host moved laterally after an unusual DNS request. Use supplied network records to support or reject each step of that narrative.
Evidence to look for
Deliver a claim-to-evidence table with timestamps and a clearly marked unknown. Treat an AI summary as a hypothesis until the underlying observations support it.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which capabilities come from the licensed sensor versus Investigator?
- Can an analyst reproduce an assisted conclusion from retained evidence?
- Which external EDR, firewall or identity permissions are required for the proposed response?