Corelight transforms network data into definitive evidence, powering AI-driven detection and expert-authored workflows, and enabling the AI SOC ecosystem.
Modern defense requires certainty, not mystery verdicts.
As AI becomes a bigger part of security operations, trust matters just as much as speed. That means building an AI SOC on provably better data, transparent detections, and agentic triage backed by auditable logic analysts can inspect and trust.
Explore Corelight's approach to a defensible AI SOC ๐ https://t.co/mwCOUWWgYl
Across these conversations, one theme surfaced repeatedly.
Investigations improve when defenders have the context needed to understand what's happening before drawing conclusions.
Whether the discussion focused on threat hunting, cloud environments, automation, or investigative workflows, the common thread was evidence-driven decision making.
#ThreatHunting #Cybersecurity #NetworkSecurity
Something new is coming to Booth #3940 at @BlackHatEvents
USA!
Meet Agent Lux, Corelight's multi-utility agentic system, built to handle the investigative volume that slows analysts down while keeping every verdict transparent and grounded in network evidence.
Stop by the booth to see Agent Lux in action and pick up an exclusive Agent Lux card deck.
Plan your visit: https://t.co/fplVvZsr86
#BlackHat #BHUSA #Cybersecurity #NetworkSecurity
Every Black Hat NOC investigation starts with network activity.
This one started with unencrypted HTTP traffic and a music trivia game at @BlackHatEvents Asia 2026.
Using passive network observation, Corelight researchers reconstructed the game's leaderboard, questions, and answers in cleartext. They then used Claude Code to demonstrate how quickly exposed scoring logic could be exploited.
The prize was low stakes. The lesson was not.
Misconfigured services and overlooked applications exist everywhere. Network visibility helps defenders see what is actually happening across the environment, not just what they expect to be there.
Read the blog: https://t.co/0qoWDi76Gj
#BlackHat #NetworkSecurity #NDR
The @blackhatevents NOC isn't a typical security environment.
Training classes, research activity, CTF traffic, attendee devices, and live conference operations all share a temporary network.
Defenders have to determine which activity is expected, which deserves investigation, and what the network evidence reveals.
Want to see that investigative mindset in action? Reserve a guided NOC tour, then stop by Booth #3940 for Vince Stoffer's theater session, "Network Visibility Stacks the Deck Against Mythos." Vince will discuss why network evidence remains a critical advantage as AI accelerates vulnerability discovery and exploitation.
See everything Corelight has planned during Black Hat ๐ https://t.co/fplVvZsr86
#BlackHat #ThreatHunting #NetworkSecurity #Cybersecurity
Deploying AI is one challenge. Trusting it is another.
As AI moves from experimentation into security operations, organizations need confidence that AI systems will behave as expected in real-world environments.
Join Corelight Co-Founder and Chief Strategy Officer Gregory Bell alongside experts from Forrester, MITRE, SimSpace, SCYTHE, and Sondera for a discussion on AI governance, validation, and operational resilienceโand what it takes to move AI from experimentation to trusted deployment.
Save your spot: https://t.co/X22GYu3Vnw
Corelight is pleased to welcome Amanda Berger as Chief Customer Officer.
Amanda brings more than 25 years of experience leading customer organizations across cybersecurity and SaaS. She'll lead our customer success organization as we continue helping customers turn network evidence into measurable outcomes, including faster investigations, fewer blind spots, and greater confidence in their defenses.
Please join us in welcoming Amanda to the team.
Read the announcement: https://t.co/LoTsL7ZnbP
Detection isn't built on one method alone.
Signatures identify known threats. Anomaly detection highlights statistical deviations. Between them is another layer: TTP-based behavioral detection, designed to identify known attacker techniques without waiting for a signature or a baseline.
Our latest blog examines where this detection layer fits within a modern detection architecture and why it helps defenders investigate activity with greater confidence.
๐ Read the blog: https://t.co/EUxdcY01N3
#ThreatDetection #NetworkSecurity
Real investigations rarely begin with a complete picture.
Locked Shields 2026 challenged defenders to investigate attacks across critical infrastructure while working through incomplete context, multiple tools, and no time to waste. Network evidence helped provide a clearer path from anomaly to investigation and from investigation to response.
Read how Corelight supported defenders during one of the world's largest live-fire cyber defense exercises.
Explore more on the blog ๐ https://t.co/EZ0Kdi5sWO
Some of the most interesting findings start with a simple question: "What else?"
At Black Hat Asia 2026, Corelight analysts investigated exposed credentials, application secrets, and infected devices. The common thread wasn't what they found. It was the curiosity to keep digging beyond the first answer.
In his latest blog, Mark Overholser shares three lessons from the Black Hat NOC and why asking one more question can change the outcome of an investigation.
๐ Read the full blog: https://t.co/zLYNh74TwM
#ThreatHunting #Cybersecurity #NetworkSecurity #BlackHa
AI can help defenders move faster.
The harder question is whether it's helping them solve the right problems.
In his latest Forbes Technology Council article, Bernard Brantley argues that AI strategy should begin with understanding your environment, the threats that matter most, and the outcomes you're trying to improve. Accelerating existing workflows comes second.
Read why AI should expand judgment, not bypass it.
Explore the full article here ๐ https://t.co/8RfiLMHbYo
Automation can help analysts process information faster.
Understanding the outcome still requires human judgment.
David Burkett discusses where automation is providing practical value today and why context remains essential when evaluating investigative findings.
๐ฅ Watch the conversation below.
#Cybersecurity #SOC #CloudSecurity
What actually powers an AI SOC?
At Black Hat USA, Corelight Co-Founder and Chief Strategy Officer Greg Bell will discuss the role of model choice versus data choice in AI-assisted investigations during his theater session at Booth #3940.
While youโre there, see Agent Lux investigate high-risk detections using high-fidelity network evidence, with transparent reasoning and evidence-backed verdicts.
Head here to see Gregโs theater session schedule, reserve a guided NOC tour, and plan your visit to Booth #3940: https://t.co/gObwgLTR52
#BlackHat #Cybersecurity #SOC #NetworkSecurity
Investigations don't end when you find something interesting.
The next question is whether you can turn that finding into a detection that catches the next occurrence.
James Pope walks through how AI-assisted detection engineering can shorten the path from network evidence to production-ready Suricata and YARA rules, without removing the human judgment required to tune, validate, and ship them.
See the findings: https://t.co/AKHzJ7s2Te
Can an AI model answer questions its data can't support?
Greg Bell argues that every data source creates a cap on inferenceโa ceiling on what an LLM can know based on the quality of the data it's given.
In this episode of Corelight DefeNDRs, Greg joins Richard Bejtlich to discuss new research showing how higher-fidelity network data helped AI agents improve threat hunting accuracy, reduce hallucinations, and solve security problems faster.
๐ง Listen now: https://t.co/Hwggxcqw6K
๐ Read the research: https://t.co/L9GGT1mcKv
Encrypted traffic doesn't always hide command-and-control activity.
While BitRAT communicates over HTTPS, investigators found that many deployments rely on a default SSL certificate that exposes a distinctive artifact in the certificate subject and issuer fields.
In this latest Corelight Labs blog, see how network evidence, Zeek, Suricata, and SIEM queries can help defenders identify BitRAT C2 without decrypting the traffic.
Read the blog ๐ https://t.co/UntSeIn61k
Every AI SOC has a ceiling.
It's set by the quality of the data available to the investigation.
Corelight evaluated the same frontier AI model against multiple network-derived data sources while keeping the tasks constant. Across threat hunting and incident response exercises, the findings were consistent: better evidence led to better investigative outcomes.
For defenders evaluating AI in the SOC, the quality of the evidence may matter more than the choice of model.
Explore the research: https://t.co/SNTr0QbuUS
#NetworkSecurity #AI #SOC
Not every suspicious event deserves the same response.
A connection involving a critical system carries different investigative weight than similar activity elsewhere in the environment.
James Pope discusses how context influences investigative priorities and why understanding what matters most to the organization remains a critical part of threat hunting.
Watch the conversation below โฌ๏ธ
#ThreatHunting #Cybersecurity #NetworkSecurity
How do you detect a threat that doesn't yet have mature public detection coverage?
When Corelight Labs analyzed ScoutC2, researchers focused on the network behavior it leaves behind. Distinctive HTTP paths, methods, headers, and payload patterns made it possible to develop high-fidelity detections using Zeek, SIEM queries, and Suricata rules.
The result is a practical walkthrough that shows defenders how to investigate and detect ScoutC2 using network evidence, with detection logic they can apply in their own environments.
Read the research: https://t.co/LRCCl5fpFM
Corelight began with a commitment to The Zeek Project.
That open source heritage still shapes how we think about network detection and response today.
As Vince Stoffer explains, Zeek remains a critical engine within the Corelight platform. Over the past decade, we've built on that foundation into a complete platform for network detection and response.
From open-source roots โก๏ธ Corelight Open NDR.