• HOME
  • CATEGORIES

    • CATEGORIES

    • Application Development

      • Observability Platforms
      • Integrated Development Environment (IDE) Software
      • Enterprise Agile Planning Tools
      • Integration Platform as a Service
      • AI-Augmented Software Testing Tools
      • View All
    • Artificial Intelligence

      • AI Code Assistants (Transitioning to AI Coding Agents)
      • Generative AI Knowledge Management Apps/General Productivity
      • AI Application Development Platforms
      • Conversational AI Platforms
      • Artificial Intelligence Applications in IT Service Management (Transitioning to AI Applications in IT Service Management)
      • View All
    • Cloud Computing

      • Backup and Data Protection Platforms
      • Cloud Database Management Systems
      • Strategic Cloud Platform Services
      • Server Virtualization (Transitioning to Server Virtualization Platforms)
      • Hybrid Cloud Storage
      • View All
    • Customer Relationship Management

      • Contact Center as a Service
      • CRM Customer Engagement Center
      • Digital Experience Platforms
      • Web Content Management
      • Field Service Management
      • View All
    • Data and Analytics

      • Analytics and Business Intelligence Platforms
      • Data Science and Machine Learning Platforms (Transitioning to AI Platforms For Data Science and Machine Learning)
      • Data Integration Tools
      • Process Mining Platforms (Transitioning to Process Intelligence Platforms)
      • Augmented Data Quality Solutions
      • View All
    • Education

      • Manager and Leadership Training
      • Corporate Learning Technologies
      • eLearning Authoring Tools
      • Higher Education Student Information System Software as a Service (Transitioning to Higher Education SaaS Student Information Systems)
      • Digital Learning Content Providers
      • View All
    • Enterprise Networking and Communications

      • Unified Communications as a Service
      • Global WAN Services
      • Intranet Packaged Solutions
      • SD-WAN
      • Edge Distribution Platforms
      • View All
    • Finance

      • Expense Management Software
      • Financial Close and Consolidation Solutions
      • Financial Planning Software
      • Cloud Financial Management Tools
      • Accounts Payable Applications
      • View All
    • Healthcare and Life Sciences

      • Medical Device Security Solutions (Transitioning to Medical Device Risk Management Platforms)
      • Health Navigation Solutions
      • Claim Editor Software
      • Revenue Cycle Management Software (Transitioning to Revenue Cycle Management Solutions)
      • Digital Health Platforms (Transitioning to Healthcare Provider Industry Cloud Platforms)
      • View All
    • Human Resources

      • Employee Recognition and Reward Systems
      • Workforce Management Applications (Transitioning to Workforce Management (WFM) Technology)
      • Digital Employee Experience Management Tools
      • Talent Acquisition (Recruiting) Suites
      • Cloud HCM Suites for Regional and/or Sub-1,000 Employee Enterprises
      • View All
    • IT Infrastructure and IoT

      • Enterprise Wired and Wireless LAN Infrastructure (Transitioning to Enterprise Wired and Wireless LAN)
      • Endpoint Management Tools
      • IT Service Management Platforms
      • Container Management
      • Infrastructure Monitoring Tools
      • View All
    • IT Security

      • Endpoint Protection Platforms
      • Email Security
      • Managed Detection and Response
      • Security Information and Event Management
      • Security Awareness Computer-Based Training
      • View All
    • Legal

      • Contract Life Cycle Management
      • Electronic Signature
      • Governance, Risk and Compliance Tools, Assurance Leaders
      • Compliance Monitoring Solutions
      • Corporate Governance Services
      • View All
    • Manufacturing

      • Enterprise Asset Management Software
      • Manufacturing Execution Systems
      • Global Industrial IoT Platforms
      • PLM Software in Discrete Manufacturing Industries
      • Computer-Aided Design (CAD) Software
      • View All
    • Marketing

      • Video Editing Software
      • Email Marketing
      • Multichannel Marketing Hubs
      • Customer Data Platforms
      • Event Marketing and Management Platforms
      • View All
    • Productivity and Collaboration

      • Document Management
      • Visual Collaboration Applications
      • Collaborative Work Management
      • Knowledge Management (KM) Software
      • Communications Platform as a Service
      • View All
    • Public Sector and Government

      • Government Budgeting and Planning Solution
      • Cloud-Based ERP for U.S. Local Government
      • Citizen Service Delivery
      • Government ERP Solutions
      • Government Contracting Software
      • View All
    • Retail

      • Digital Commerce
      • Digital Commerce Payment Vendors (Transitioning to Digital Commerce Payment Platforms)
      • Retail Assortment Management Applications: Long Life Cycle Products
      • Retail Workforce Management Applications (Transitioning to Retail Workforce Management Technology)
      • Digital Shelf Analytics
      • View All
    • Sales

      • Sales Force Automation Platforms (Transitioning to CRM Sales Platforms)
      • Revenue Enablement Platforms
      • Revenue Intelligence (Transitioning to Revenue Action Orchestration)
      • Configure, Price and Quote Applications
      • Search and Product Discovery
      • View All
    • Supply Chain Management

      • Supply Chain Planning Solutions
      • Transportation Management Systems
      • Real-Time Transportation Visibility Platforms
      • Warehouse Management Systems
      • Supply Chain Strategy, Planning and Operations Consulting
      • View All
    • Utilities

      • Geospatial Information Systems for Energy and Utilities
      • Mobile Workforce Management Software for Utilities (Transitioning to Mobile Workforce Management Solutions for Power and Utilities)
      • Energy Management and Optimization Systems
      • Energy Trading and Risk Management
      • Advanced Distribution Management Systems
      • View All
    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

      • Application Development
      • Artificial Intelligence
      • Cloud Computing
      • Customer Relationship Management
      • Data and Analytics
      • Education
      • Enterprise Networking and Communications
      • Finance
      • Healthcare and Life Sciences
      • Human Resources
      • IT Infrastructure and IoT
      • IT Security
      • Legal
      • Manufacturing
      • Marketing
      • Productivity and Collaboration
      • Public Sector and Government
      • Retail
      • Sales
      • Supply Chain Management
      • Utilities
      Browse All Categories

      Application Development

      69 markets
      • Observability Platforms
      • Integrated Development Environment (IDE) Software
      • Enterprise Agile Planning Tools
      • Integration Platform as a Service
      • AI-Augmented Software Testing Tools
      • API Management
      • Enterprise Low-Code Application Platforms
      • Robotic Process Automation
      • DevOps Platforms (Transitioning to DevSecOps Platforms)
      • Business Process Automation Tools
      • Enterprise Architecture Tools
      • Business Orchestration and Automation Technologies
      • Custom Software Development Services
      • Code Review Tools
      • Digital Adoption Platforms
      • Domain Registrars
      • Public Cloud IT Transformation Services (Transitioning to Public Cloud Optimization and Transformation Services)
      • Game Engine Software
      • Website Builders
      • Developer Productivity Insight Platforms
      • AI Agents for Application Developers
      • Application Platforms (Transitioning to Cloud-Native Application Protection Platforms)
      • Feature Management
      • Application Crowdtesting Services
      • Test Data Management
      • API Generation Software
      • Prototyping Software
      • Mobile App Analytics
      • AI-Augmented Code Modernization Tools
      • Virtual Reality Development Software
      • Application Testing Services, Worldwide (Transitioning to Quality Engineering Services)
      • Green Software Engineering
      • Application Integration Platforms
      • Event Brokers
      • Digital Twin of an Organization Platforms
      • Independent Third-Party Software Support of Megavendors
      • Microsoft 365 Implementation and Support Services
      • Application Development Life Cycle Management (Transitioning to DevOps Platforms)
      • BPM-Platform-Based Case Management Frameworks
      • Microsoft Product Support Services
      • Product Roadmapping Tools for Software Engineering
      • Multiexperience Development Platforms
      • Application Portfolio Management Tools
      • Application Composition Platform
      • Internal Developer Portals
      • AI Agent Development Platforms for Software Engineering
      • Cloud Development Environments
      • Mobile Development Frameworks (Transitioning to Web and Mobile Development Frameworks)
      • Load Testing Tools
      • Blockchain Consulting and Proof-of-Concept Development Services
      • B2B Gateway Software
      • Citizen Application Development Platforms
      • Mobile Application Testing Services
      • SAP S/4HANA Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • Oracle Cloud Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • SAP Application Services, Worldwide
      • SAP SuccessFactors Service Providers (Transitioning to Cloud ERP Services)
      • Service Mesh
      • Value Stream Management Platforms
      • Business-Outcome-Driven Enterprise Architecture Consulting (Retired)
      • Oracle Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • Rapid Mobile App Development Tools
      • SAP Selective Test Data Management Tools
      • API and MCP Testing Tools
      • Augmented Reality Development Software
      • Blockchain as a Service
      • Mobile Application Management (Transitioning to Endpoint Management Tools)
      • Mobile Back-End Services
      • R&D Outsourcing Providers
      View More
  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Corelight Open NDR Platform
Logo of Corelight Open NDR Platform

Corelight Open NDR Platform

byCorelight
in
4.8
Market Presence: Network Detection and Response, Intrusion Detection and Prevention Systems

Overview

Product Information on Corelight Open NDR Platform

Updated 21st October 2025

What is Corelight Open NDR Platform?

Corelight's Open NDR Platform transforms network and cloud activity into evidence so defenders can stay ahead of ever-changing attacks. Delivered through an open, extensible architecture powered by Zeek, Suricata, and YARA, it combines network security monitoring, intrusion detection, static file analysis, AI, and Smart PCAP in one platform. Corelight applies the right detection approach per threat, using machine learning, behavioral analytics, and signatures to reduce false positives and accelerate detection engineering response time. By correlating alerts, packets, and context into structured, comprehensive evidence, Corelight enhances visibility, analytics, and investigation speed while integrating seamlessly with existing SIEM, XDR, and SOAR tools.

Corelight Open NDR Platform Pricing

Corelight Open NDR Platform Product Images

Prioritize threats at a glance
Prioritize threats at a glance
Simplify investigations
Simplify investigations
Actionable next-step guidance
Actionable next-step guidance

Overall experience with Corelight Open NDR Platform

SENIOR SECURITY ANALYST
50M - 250M USD, IT Services
FAVORABLE

“Corelight NDR enabling streamlined and precise incident analysis through network metadata”

5.0
Nov 20, 2025
Corelight NDR is an essential tool that greatly simplifies the detection and triage of security events through network data. Evidence collected through the sensor simplifies detection of malicious behavior, as well as providing immediate insight into all the affected machines. It provides a great platform to analyze and find irregularities and misconfigurations in the network. The provided data can be directly utilized for system and network security hardening as well as a verification method for validating hardening efforts. The solution just works and usually there is no need for customer support. Nevertheless, when needed, customer support is fast to respond and resolve any issues that might arise.
IT Security & Risk Management Associate
50M - 250M USD, Miscellaneous
CRITICAL

“Challenges With Centralized Management In Multi-Environment Deployments Of Sensor Networks”

3.0
Dec 18, 2025
I feel this vendor could be better at listening to and working with customers to provide product improvement in a timely manner

About Company

Company Description

Updated 12th December 2024

Corelight is a company that primarily focuses on network security. Its objective is to transform network and cloud data into detailed evidence to help counter ever-evolving cyber threats. The company offers an open Network Detection and Response (NDR) platform that provides a comprehensive, correlated view of the network, granting unmatched visibility to users. With the advantage of swift investigation, expert-like cyber threat hunting and potential attack disruption capabilities, Corelight targets to enhance cybersecurity preparedness. It offers both on-premise and cloud-based sensors capable of capturing standard industry telemetry and insights that align with pre-existing user tools and processes. Clients of Corelight span diverse sectors, including large scale businesses, government agencies and research institutions.

Company Details

Updated 12th August 2025
Company type
Private
Year Founded
2016
Head office location
San Francisco, United States
Number of employees
201 - 500
Website
https://www.corelight.com

Do You Manage Peer Insights at Corelight?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

User Sentiment About Corelight Open NDR Platform
Reviewer Insights for: Corelight Open NDR Platform
Performance of Corelight Open NDR Platform Across Market Features

Corelight Open NDR Platform Likes & Dislikes

Like

Ease of deployment and implementation. Quick deployment in the environment without the need of installing additional agents. After providing network traffic to the sensor, data immediately shows up in the Corelight console. Extraction of network data in a minimal and easily readable format that makes security triage and analysis faster and more straightforward. Additionally, if any alert is detected, it enables in depth analysis of network packets which are captured through the efficient SmartPCAP technology. Encrypted traffic analysis provides high fidelity insights into encrypted traffic (e.g., HTTPS, SSH, VPN, and DNS over TLS) without the need for traffic decryption. The underlying engine enables extraction of all relevant data from the encrypted traffic with no impact on the traffic analysis performance. Enables capturing of files across all analyzed traffic and storage of files for automated analysis. This is further enhanced by the YARA scanning functionality that detects potentially malicious files transferred through the network. Reliability and speed of traffic capture, data collection and data analytics. Traffic is parsed and quickly forwarded to the Corelight SIEM where it is available for analysis in less than a minute. Readiness of technical and customer support to jump on a call and discuss improvements to the platform provides peace of mind when using the solution. The Corelight team really aims at making a quality product that will streamline detection and response activities as much as possible by providing valuable information to security analysts.

Like

FleetManager

Like

The clarity and structure of the data. Corelight gives us high-fidelity, well-enriched logs that are actionable instead of chaotic. The detections are more organized, the data is richer, and investigations move faster because we are able to lay everything out in a way that makes sense. Sensor management is easy and the overall stability of the sensors has been a major plus. The product is consistently working towards reducing the noise and that's rare in this space.

Dislike

Integration with EDR vendors - Integration exists but is limited to querying EDR vendors API endpoints. This can provide great context but it is far from a fully integrated console that would integrate EDR and NDR telemetry into one timeline. Limitations on Alerting capabilities - Currently one can only create alerts based on Zeek and Suricata detections. There is no ability to create custom alerts in the Investigator SIEM based on the collected network data. Cloud traffic inspection can incur sizeable additional costs - If using a cloud provider that doesn't natively support Cloud Network TAPs the price hike for monitoring cloud network infrastructure is significant.

Dislike

The lack of having fully centralized operational management in environments with a large number of sensors deployed across multiple environments

Dislike

The product is incredibly powerful, but some tuning requires trial and error before everything aligns the way you want. Certain detections and log types can feel a bit rigid in terms of customization, and more granular configuration options would help streamline deployments. Additionally, scaling log volume can overwhelm our SIEM licensing, so it requires careful planning to avoid ingest bloat. None of these are deal-breakers, but they are areas where more flexibility could make the experience better.

Top Corelight Open NDR Platform Alternatives

Logo of Darktrace / NETWORK
1. Darktrace / NETWORK
4.8
(607 Ratings)
Logo of Vectra AI Platform
2. Vectra AI Platform
4.8
(451 Ratings)
Logo of RevealX
3. RevealX
4.7
(253 Ratings)
View All Alternatives

Peer Discussions

Corelight Open NDR Platform Reviews and Ratings

4.8

(128 Ratings)

Rating Distribution

5 Star
80%
4 Star
19%
3 Star
1%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.6

Integration & Deployment

4.7

Service & Support

4.9

Product Capabilities

4.7

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • SENIOR SECURITY ANALYST
    50M-1B USD
    IT Services
    Review Source

    Corelight NDR enabling streamlined and precise incident analysis through network metadata

    5.0
    Nov 20, 2025
    Corelight NDR is an essential tool that greatly simplifies the detection and triage of security events through network data. Evidence collected through the sensor simplifies detection of malicious behavior, as well as providing immediate insight into all the affected machines. It provides a great platform to analyze and find irregularities and misconfigurations in the network. The provided data can be directly utilized for system and network security hardening as well as a verification method for validating hardening efforts. The solution just works and usually there is no need for customer support. Nevertheless, when needed, customer support is fast to respond and resolve any issues that might arise.
  • IT SECURITY & RISK MANAGEMENT ASSOCIATE
    50M-1B USD
    Transportation
    Review Source

    Corelight Improves Network Visibility But Requires Careful Tuning and SIEM Planning

    5.0
    Nov 20, 2025
    Our experience with Corelight has been consistently strong. The platform delivers reliable, high-quality network visibility without drowning us in noise, and it has integrated strongly with our existing SIEM and workflows. The sensors have remained stable and easy to manage through the management application, and the data fidelity has improved our ability to investigate suspicious activity in both IT and OT. The support team has been responsive, knowledgeable, and genuinely invested in assisting us optimize our deployment. Corelight has made our detection and response efforts significantly more efficient and more confident.
  • Manager of IT Services
    10B+ USD
    IT Services
    Review Source

    Corelight's data and evidence is the real hero

    5.0
    Feb 12, 2026
    It's been a breath of fresh air compared to the "black box" AI tools that dominate the NDR market. Most tools give you a high-level alert and then leave you to guess what actually happened. Corelight gives you evidence first. It is a large data volume, but once we turned on our ingest and got Zeek logs flowing into our SIEM, the speed of our investigations doubled. It's an impactful pro tool that doesn't hold your hand, but doesn't lie to you.
  • Manager, IT Security and Risk Management
    Gov't/PS/Ed
    Government
    Review Source

    Death of NDR is greatly exaggerated

    5.0
    Jan 14, 2026
    Corelight have been great and engaged with us from initial deployment stages through to ongoing maintenance in production. Product gets updated frequently with new functionality that is genuinely useful capability additions.
  • Engineering Manager
    50M-1B USD
    IT Services
    Review Source

    Excellent customer support and GUI makes administration simple

    5.0
    Jan 14, 2026
    Corelight staff have been friendly, knowledgeable, and prompt about providing support whenever we have asked, which has occurred on a range of topics over the course of the last year. I have been impressed with their level of responsiveness compared to other vendors, and I have not had a single negative interaction with Corelight even while troubleshooting product problems or issues, which says a lot about their staff's professionalism and courtesy.
...
Showing Result 1-5 of 130

Recommended Gartner Research

  • Magic Quadrant for Network Detection and Response

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.