Corelight
Open NDR platform built on the open-source Zeek network monitoring framework
Pricing: Contact for pricing
Updated June 2026.
What is Corelight?
Corelight is a network detection and response (NDR) vendor founded in 2013 by the creators of the open-source Zeek framework (formerly Bro). Its Open NDR Platform combines Zeek network evidence with Suricata intrusion detection, YARA file analysis, behavioral analytics, machine learning, and packet capture for threat detection, investigation, and incident response. It is positioned as an open-core product and integrates with SIEM and XDR tools, supporting on-premise appliances, virtual and software sensors, and cloud deployments across AWS, Azure, and GCP. Corelight remains a steward of the Zeek project.
- ✓ Built on the open-source Zeek standard, producing high-fidelity, well-enriched network logs
- ✓ Combines Zeek evidence with Suricata IDS and packet capture for detection and forensic context
- ✓ Flexible deployment across appliances, virtual sensors, and major cloud providers
- ✗ Reported learning curve; better suited to larger organizations and experienced SOC teams
- ✗ Alerting reported as limited to Zeek and Suricata detections
- ✗ Total cost can be high when feeding ingest-priced SIEMs, and pricing is not publicly listed
Key Features
Sources & references
Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.
Spot an error, or do you represent Corelight? Request a correction.
Quick Info
| Pricing | Contact for pricing |
| Model | Open source + Enterprise subscription |
| Founded | 2013 |
| Cloud | Yes |
| Self-Hosted | Yes |
| Open Source | Yes |
Last updated: Jun 18, 2026
Corelight Alternatives
View All AlternativesAI-driven cyber defense using self-learning technology...Vectra AI
AI-powered NDR with Attack Signal Intelligence for hybrid cl...ExtraHop
Cloud-native NDR with line-rate network traffic analysis...Stamus Networks
Suricata-based network detection and response with an open-s...Arista NDR
Agentless, AI-assisted network detection and response for ca...