Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Corelight offers the advantages of Zeek without the complications associated with Linux, network interface card issues, or the risk of packet loss. Setting it up is a matter of minutes rather than an extensive timeline, allowing your skilled personnel to focus on threat hunting instead of resolving technical glitches. This robust platform, rooted in open-source technology, provides you with full access to your metadata, enabling customization and extension of your capabilities, all while being part of an engaging community. We have assembled a top-tier team of Zeek specialists and contributors, supported by a world-class customer care team that consistently impresses clients with their exceptional expertise and quick response times. With the proactive and secure Corelight Dynamic Health Check feature activated, your Corelight Sensor transmits performance data back to Corelight, allowing for the early detection of potential issues like disk failures or unusual performance metrics. This ensures that your network remains secure and operationally efficient at all times. Ultimately, Corelight empowers organizations to safeguard their networks with confidence and efficiency.

Description

To effectively identify sophisticated threats, it is essential to conduct thorough inspection, extraction, and real-time analysis of all types of content traversing the network. Fidelis' network detection and response technology systematically scans all ports and protocols in both directions, gathering extensive metadata that serves as the foundation for robust machine-learning analytics. By utilizing sensors for direct, internal, email, web, and cloud communications, you achieve comprehensive network visibility and coverage. The tactics, techniques, and procedures (TTPs) of identified attackers are aligned with the MITRE ATT&CK™ framework, enabling security teams to proactively address potential threats. While threats may attempt to evade detection, they ultimately cannot escape. You can automatically profile and categorize IT assets and services, including enterprise IoT devices, legacy systems, and shadow IT, to create a detailed map of your cyber landscape. Furthermore, when combined with Fidelis' endpoint detection and response offering, you obtain a software asset inventory linked to known vulnerabilities, such as CVE and KB references, along with an assessment of security hygiene concerning patches and the status of endpoints. This comprehensive approach equips organizations with the tools needed to maintain a resilient cybersecurity posture.

API Access

Has API No 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

AWS Marketplace Yes 
Amazon S3 Yes 
Chronicle Yes 
CrowdStrike Falcon Yes 
Databricks Yes 
Devo Yes 
Elastic Cloud Yes 
EndaceProbe Yes 
Fidelis LRM No 
Gigamon Yes 
Google Digital Risk Protection No 
Humio Yes 
Intellicta No 
Palo Alto Networks DNS Security Service Yes 
Splunk Cloud Platform Yes 
Splunk SOAR Yes 
Sumo Logic Yes 
ThreatQ Yes 

Integrations

AWS Marketplace No 
Amazon S3 No 
Chronicle No 
CrowdStrike Falcon No 
Databricks No 
Devo No 
Elastic Cloud No 
EndaceProbe No 
Fidelis LRM Yes 
Gigamon No 
Google Digital Risk Protection Yes 
Humio No 
Intellicta Yes 
Palo Alto Networks DNS Security Service No 
Splunk Cloud Platform No 
Splunk SOAR No 
Sumo Logic No 
ThreatQ No 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Pricing Details

No price information available.
Free Trial Yes 
Free Version No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) Yes 
In Person No 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) Yes 
In Person Yes 

Vendor Details

Company Name

Corelight

Founded

2013

Country

United States

Website

www.corelight.com

Vendor Details

Company Name

Fidelis Security

Founded

2002

Country

United States

Website

fidelissecurity.com/products/network/

Product Features

Network Traffic Analysis (NTA)

Anomalous Behavior Detection No 
High Bandwidth Usage Monitoring No 
Historical Behavior Data No 
Identify High Network Traffic Sources No 
Network Transaction Visibility No 
Stream Data to IDR or Data Lake No 
Traffic Decryption No 

Product Features

Data Loss Prevention

Compliance Reporting No 
Incident Management No 
Policy Management No 
Sensitive Data Identification No 
Web Threat Management No 
Whitelisting / Blacklisting No 

Network Traffic Analysis (NTA)

Anomalous Behavior Detection No 
High Bandwidth Usage Monitoring No 
Historical Behavior Data No 
Identify High Network Traffic Sources No 
Network Transaction Visibility No 
Stream Data to IDR or Data Lake No 
Traffic Decryption No 

Alternatives

NetworkMiner Reviews

NetworkMiner

Netresec

Alternatives

Fidelis Elevate Reviews

Fidelis Elevate

Fidelis Security
Fidelis Elevate Reviews

Fidelis Elevate

Fidelis Security
Zeek Reviews

Zeek

The Zeek Project
IronDefense Reviews

IronDefense

IronNet Cybersecurity