Corelight provides an open network detection and response (NDR) platform that utilizes network traffic analysis and YARA-based pattern matching to enhance threat detection rates by up to 35%. The platform addresses visibility gaps and reduces triage time by up to 50%, enabling security teams to respond more effectively to cyber threats.
Funding
$150M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.




Founders
Product
Problem
Security teams often lack comprehensive visibility into network traffic within cloud environments, hindering their ability to detect and respond to threats effectively. Traditional security tools may not be optimized for the dynamic and distributed nature of cloud infrastructure, leading to blind spots and delayed incident response. The increasing complexity of hybrid and multi-cloud environments further exacerbates these visibility challenges.
Solution
Corelight's Open NDR platform provides network detection and response capabilities tailored for cloud environments, transforming cloud traffic into security-centric evidence. By enriching network traffic with cloud control plane data, the platform delivers complete visibility across hybrid and multi-cloud environments. The platform's cloud-native detections and analytics enable security teams to identify and respond to threats in real time, while reducing log volume by 50-80%. Corelight's solution streamlines analyst workflows by consolidating datasets and toolsets, increasing efficiency and accelerating incident response.
Target Audience
The primary target audience includes security operations center (SOC) teams, incident responders, and threat hunters who need comprehensive network visibility and advanced threat detection capabilities in cloud environments.
Features
- Real-time cloud threat detection and accelerated incident response
- Complete network visibility in AWS, GCP, and Azure environments
- Uniform telemetry across hybrid and multi-cloud deployments
- Cloud-native detections and analytics optimized for cloud traffic
- Integration with cloud control plane data for enhanced context
- Reduction in log volume by 50-80%
- Identification and mapping of cloud services to hosts
- Support for Zeek, Suricata, and YARA for comprehensive threat detection