Network detection and response platform built on Zeek, powering AI-driven SOC workflows
Corelight operates an open NDR platform that converts raw network telemetry into actionable security evidence. The stack reflects a mature detection-focused engineering org: Zeek and Suricata for packet analysis, Python for custom logic, Kafka and Elasticsearch for data pipelines, and Splunk for SIEM integration. Recent adoption of Agentforce, OpenAI, and Anthropic signals a shift toward AI-assisted threat hunting and automation—matching their stated focus on AI-driven detection. Sales velocity is accelerating with leadership hiring, but pain points around incident response delays and scaling data pipelines suggest the product is hitting performance boundaries as customers deploy at enterprise scale.
Notable leadership hires: Director of Sales
Corelight builds an open network detection and response platform deployed as on-premise and cloud sensors to capture structured network telemetry and feed it to security operations centers. The platform specializes in transforming network traffic data into correlated evidence for threat detection, investigation, and hunting workflows. Customers include Fortune 500 companies, government agencies, and research universities. The engineering org is actively scaling internal infrastructure to handle massive network data volumes while systematizing product processes and delivery reliability. Sales operations span the United States, Germany, Australia, and India.
Zeek, Suricata, YARA, Python, Bash, AWS, Azure, GCP, Kafka, Elasticsearch, Splunk, Terraform, and Ansible. Currently adopting OpenAI, Anthropic, and Salesforce Agentforce for AI-driven features.
Open NDR platform releases, SIEM query/dashboard implementation, SOC/IR workflow automation, custom threat hunting content, and scalable test infrastructure for high-performance API services.
Other companies in the same industry, closest in size
Corelight's technology stack, projects, and hiring signals are inferred from public hiring and company data — career pages, public listings, and company web presence — then clustered and de-duplicated. Figures are estimates that refresh over time. Read our full methodology →
This is not an official vendor or customer list. It is a technology-adoption signal inferred from public data, intended for B2B research.