Logo

Corelight License

Corelight License provides access to enterprise Network Detection and Response (NDR) and network security monitoring capabilities designed to turn network traffic into high-fidelity security evidence. Corelight combines the open-source technologies Zeek and Suricata with its own detection, analytics, packet-capture, threat-intelligence, and investigation capabilities to help security teams identify threats that may not be visible through endpoint telemetry alone.

Quick Benefits

corelight license

Corelight License At a Glance

What it is: Network Detection and Response and network security monitoring platform

Vendor: Corelight

Primary platform: Corelight Open NDR Platform

Primary products: Corelight Sensors, Corelight Investigator, Smart PCAP, and Detection Collections

Primary role: Network visibility, threat detection, investigation, threat hunting, and response

Security areas: NDR, network security monitoring, intrusion detection, threat hunting, network forensics, and incident response

Core technologies: Zeek, Suricata, YARA, AI/ML detection, behavioral analytics, and Smart PCAP

Deployment models: Physical appliance, virtual machine, cloud, software sensor, SaaS, hybrid, and air-gapped environments

Management: Corelight Fleet Manager and Investigator

Corelight price quote banner

Need Corelight Pricing?

Tell us your requirements and receive a tailored quote for your Corelight licensing, network detection and response, network traffic analysis, threat hunting, packet capture, and deployment needs.

Get Price Quote →

License Overview

A Corelight License determines access to Corelight’s network visibility, detection, investigation, and response capabilities. Corelight licensing is not based on a single universal metric across every component.

The licensing requirements can vary according to the sensor type and the services deployed.

Corelight Sensors transform network traffic into security evidence and are available as hardware appliances, virtual machines, cloud instances, and software sensors. Investigator is a SaaS-based network detection and response solution, and its usage is measured on a Gbps and/or GB basis according to the applicable sensor types and purchased capacity.

Additional platform capabilities can also be licensed as modules. For example, Corelight Threat Intelligence is a licensed feature for Corelight Sensors and Investigator, while AI/ML detection is a subscription-based module that can be purchased with Corelight Sensors.

Important licensing factors can therefore include:

How Corelight Licensing Works

Corelight licensing begins with determining where network visibility is required and how much traffic needs to be analyzed.

A typical deployment follows this model:

Network Traffic
→ Mirror or route relevant traffic to Corelight Sensors

Network Analysis
→ Parse traffic and generate structured network evidence

Detection
→ Apply signatures, behavioral analytics, AI/ML, and threat intelligence

Investigation
→ Correlate alerts with network evidence and historical activity

Response
→ Connect findings with EDR, SIEM, SOAR, firewall, and other security controls

This architecture allows Corelight to operate as a network telemetry and detection layer alongside existing endpoint and security platforms.

Corelight Platform Overview

Corelight Component Primary Purpose
Corelight Sensors Capture and analyze network traffic and generate high-fidelity network evidence
Corelight Investigator SaaS-based investigation, detection, and response platform
Smart PCAP Capture selected packets for deeper forensic investigation
Network Monitoring with Zeek Generate detailed network metadata and protocol-level visibility
Suricata IDS Signature-based intrusion detection
YARA File Analysis Pattern-based analysis of files observed in network traffic
AI/ML Detection Identify anomalous and evasive network behavior
Threat Intelligence Enrich network evidence with contextualized threat indicators
Detection Collections Add curated detection and protocol-specific security content

Licensing Options and Models

Licensing Option Description Suitable For
Corelight Sensor Subscription Software subscription required for supported Corelight Sensor deployments Organizations requiring network visibility and detection
Hardware Sensor + Software Subscription Hardware appliance paired with an associated software subscription High-throughput data center and enterprise networks
Virtual Sensor Subscription Corelight Sensor deployed as a virtual machine Virtualized infrastructure
Cloud Sensor Subscription Sensor deployment for supported cloud environments AWS, Azure, GCP, and hybrid cloud architectures
Corelight Investigator SaaS-based NDR and investigation capability measured according to applicable capacity SOC and incident-response teams
Smart PCAP Selective packet capture for deeper forensic analysis Organizations requiring packet-level investigation
AI/ML Detection Subscription-based detection module for Corelight Sensors Organizations requiring behavioral and ML-based detection
Threat Intelligence Licensed threat-intelligence capability for Sensors and Investigator SOC teams requiring IOC enrichment
Detection Collections Additional curated detection and protocol-analysis content Organizations requiring specialized network coverage
Enterprise Support Enhanced support for mission-critical deployments Large and critical infrastructure environments

Features and Benefits

Network Detection and Response

Corelight’s primary security function is Network Detection and Response.

The platform analyzes network activity to provide visibility into communications that may not be fully represented in endpoint telemetry.

This can help security teams investigate:

Corelight describes its Open NDR architecture as combining network visibility, layered detection, and incident-response capabilities around network evidence.

Zeek-Based Network Monitoring

Zeek is foundational to Corelight’s network monitoring architecture.

It generates structured information about network activity and protocols, allowing security teams to investigate connections without relying exclusively on raw packet captures.

This can provide visibility into:

The resulting network evidence can be exported to existing SIEM, XDR, SOAR, and security analytics platforms.

Intrusion Detection with Suricata

Corelight integrates Suricata as an intrusion-detection layer within its Open NDR architecture.

This adds signature-based detection alongside behavioral and AI/ML analytics.

Using multiple detection layers allows security teams to combine known-threat detection with analysis of unusual or previously unseen network activity.

Compatibility and Requirements

Before selecting a Corelight License, organizations should evaluate:

Corelight supports physical, virtual, cloud, and software-based sensor options, allowing the deployment architecture to be matched to the organization’s infrastructure.

Activation and Deployment

A typical Corelight deployment includes:

Pricing and Quote Process

Pricing for Corelight License depends on the sensor architecture, traffic capacity, Investigator requirements, selected modules, and deployment environment.

Before requesting a quote, prepare:

For Investigator specifically, capacity is measured using Gbps and/or GB according to the applicable Sensor type and purchased capacity. Accurate traffic sizing is therefore more useful than simply counting network devices. Two organizations with the same number of switches can require very different Corelight licensing if their traffic volumes differ significantly.

Corelight pricing depends on your product capabilities, network traffic visibility requirements, deployment model, packet capture needs, license term, and support requirements.

Request Corelight Quote →

Frequently Asked Questions