Corelight License provides access to enterprise Network Detection and Response (NDR) and network security monitoring capabilities designed to turn network traffic into high-fidelity security evidence. Corelight combines the open-source technologies Zeek and Suricata with its own detection, analytics, packet-capture, threat-intelligence, and investigation capabilities to help security teams identify threats that may not be visible through endpoint telemetry alone.
Quick Benefits
- Network Detection and Response (NDR)
- High-fidelity network security evidence
- Zeek-based network monitoring
- Suricata-based intrusion detection
- Network traffic analysis
- Threat detection and behavioral analytics
- Threat hunting capabilities
- Smart packet capture
- Malware file analysis with YARA
- Threat intelligence enrichment
- AI/ML-based detection

Corelight License At a Glance
What it is: Network Detection and Response and network security monitoring platform
Vendor: Corelight
Primary platform: Corelight Open NDR Platform
Primary products: Corelight Sensors, Corelight Investigator, Smart PCAP, and Detection Collections
Primary role: Network visibility, threat detection, investigation, threat hunting, and response
Security areas: NDR, network security monitoring, intrusion detection, threat hunting, network forensics, and incident response
Core technologies: Zeek, Suricata, YARA, AI/ML detection, behavioral analytics, and Smart PCAP
Deployment models: Physical appliance, virtual machine, cloud, software sensor, SaaS, hybrid, and air-gapped environments
Management: Corelight Fleet Manager and Investigator
License Overview
A Corelight License determines access to Corelight’s network visibility, detection, investigation, and response capabilities. Corelight licensing is not based on a single universal metric across every component.
The licensing requirements can vary according to the sensor type and the services deployed.
Corelight Sensors transform network traffic into security evidence and are available as hardware appliances, virtual machines, cloud instances, and software sensors. Investigator is a SaaS-based network detection and response solution, and its usage is measured on a Gbps and/or GB basis according to the applicable sensor types and purchased capacity.
Additional platform capabilities can also be licensed as modules. For example, Corelight Threat Intelligence is a licensed feature for Corelight Sensors and Investigator, while AI/ML detection is a subscription-based module that can be purchased with Corelight Sensors.
Important licensing factors can therefore include:
- Network traffic throughput
- Sensor capacity
- Data volume
- Number and type of sensors
- Investigator requirements
- Packet-capture requirements
- Retention requirements
- Threat intelligence requirements
- AI/ML detection requirements
- Detection collections
How Corelight Licensing Works
Corelight licensing begins with determining where network visibility is required and how much traffic needs to be analyzed.
A typical deployment follows this model:
Network Traffic
→ Mirror or route relevant traffic to Corelight Sensors
Network Analysis
→ Parse traffic and generate structured network evidence
Detection
→ Apply signatures, behavioral analytics, AI/ML, and threat intelligence
Investigation
→ Correlate alerts with network evidence and historical activity
Response
→ Connect findings with EDR, SIEM, SOAR, firewall, and other security controls
This architecture allows Corelight to operate as a network telemetry and detection layer alongside existing endpoint and security platforms.
Corelight Platform Overview
| Corelight Component | Primary Purpose |
|---|---|
| Corelight Sensors | Capture and analyze network traffic and generate high-fidelity network evidence |
| Corelight Investigator | SaaS-based investigation, detection, and response platform |
| Smart PCAP | Capture selected packets for deeper forensic investigation |
| Network Monitoring with Zeek | Generate detailed network metadata and protocol-level visibility |
| Suricata IDS | Signature-based intrusion detection |
| YARA File Analysis | Pattern-based analysis of files observed in network traffic |
| AI/ML Detection | Identify anomalous and evasive network behavior |
| Threat Intelligence | Enrich network evidence with contextualized threat indicators |
| Detection Collections | Add curated detection and protocol-specific security content |
Licensing Options and Models
| Licensing Option | Description | Suitable For |
|---|---|---|
| Corelight Sensor Subscription | Software subscription required for supported Corelight Sensor deployments | Organizations requiring network visibility and detection |
| Hardware Sensor + Software Subscription | Hardware appliance paired with an associated software subscription | High-throughput data center and enterprise networks |
| Virtual Sensor Subscription | Corelight Sensor deployed as a virtual machine | Virtualized infrastructure |
| Cloud Sensor Subscription | Sensor deployment for supported cloud environments | AWS, Azure, GCP, and hybrid cloud architectures |
| Corelight Investigator | SaaS-based NDR and investigation capability measured according to applicable capacity | SOC and incident-response teams |
| Smart PCAP | Selective packet capture for deeper forensic analysis | Organizations requiring packet-level investigation |
| AI/ML Detection | Subscription-based detection module for Corelight Sensors | Organizations requiring behavioral and ML-based detection |
| Threat Intelligence | Licensed threat-intelligence capability for Sensors and Investigator | SOC teams requiring IOC enrichment |
| Detection Collections | Additional curated detection and protocol-analysis content | Organizations requiring specialized network coverage |
| Enterprise Support | Enhanced support for mission-critical deployments | Large and critical infrastructure environments |
Features and Benefits
Network Detection and Response
Corelight’s primary security function is Network Detection and Response.
The platform analyzes network activity to provide visibility into communications that may not be fully represented in endpoint telemetry.
This can help security teams investigate:
- Command-and-control activity
- Lateral movement
- Suspicious network connections
- Data transfers
- Anomalous behavior
- Network-based attacks
Corelight describes its Open NDR architecture as combining network visibility, layered detection, and incident-response capabilities around network evidence.
Zeek-Based Network Monitoring
Zeek is foundational to Corelight’s network monitoring architecture.
It generates structured information about network activity and protocols, allowing security teams to investigate connections without relying exclusively on raw packet captures.
This can provide visibility into:
- DNS
- HTTP
- TLS
- SSH
- SMB
- RDP
- Other supported network protocols
The resulting network evidence can be exported to existing SIEM, XDR, SOAR, and security analytics platforms.
Intrusion Detection with Suricata
Corelight integrates Suricata as an intrusion-detection layer within its Open NDR architecture.
This adds signature-based detection alongside behavioral and AI/ML analytics.
Using multiple detection layers allows security teams to combine known-threat detection with analysis of unusual or previously unseen network activity.
Compatibility and Requirements
Before selecting a Corelight License, organizations should evaluate:
- Average network throughput
- Peak traffic throughput
- Number of monitoring points
- Data center architecture
- East-West traffic requirements
- North-South traffic requirements
- Cloud traffic
- OT/ICS networks
- Encrypted traffic visibility
- Required data retention
- Packet-capture requirements
- SIEM integration
- XDR integration
- SOAR integration
- EDR integration
- Sensor deployment model
- Investigator capacity
Corelight supports physical, virtual, cloud, and software-based sensor options, allowing the deployment architecture to be matched to the organization’s infrastructure.
Activation and Deployment
A typical Corelight deployment includes:
- Determine monitored network segments
- Calculate average and peak traffic
- Select the appropriate Sensor architecture
- Determine required software subscriptions
- Deploy physical, virtual, or cloud Sensors
- Configure traffic sources such as TAPs or SPAN
- Configure Fleet Manager
- Enable required detection modules
Pricing and Quote Process
Pricing for Corelight License depends on the sensor architecture, traffic capacity, Investigator requirements, selected modules, and deployment environment.
Before requesting a quote, prepare:
- Average network throughput
- Peak network throughput
- Number of network monitoring points
- Number of physical Sensors
- Number of virtual or cloud Sensors
- Investigator requirements
- Data volume
- Retention requirements
- Smart PCAP requirements
For Investigator specifically, capacity is measured using Gbps and/or GB according to the applicable Sensor type and purchased capacity. Accurate traffic sizing is therefore more useful than simply counting network devices. Two organizations with the same number of switches can require very different Corelight licensing if their traffic volumes differ significantly.
Corelight pricing depends on your product capabilities, network traffic visibility requirements, deployment model, packet capture needs, license term, and support requirements.
