• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Corelight Open NDR Platform
Logo of Corelight Open NDR Platform

Corelight Open NDR Platform

byCorelight
in
4.8
Market Presence: Network Detection and Response, Intrusion Detection and Prevention Systems (Retired)

Overview

Product Information on Corelight Open NDR Platform

Updated 21st October 2025

What is Corelight Open NDR Platform?

Corelight's Open NDR Platform transforms network and cloud activity into evidence so defenders can stay ahead of ever-changing attacks. Delivered through an open, extensible architecture powered by Zeek, Suricata, and YARA, it combines network security monitoring, intrusion detection, static file analysis, AI, and Smart PCAP in one platform. Corelight applies the right detection approach per threat, using machine learning, behavioral analytics, and signatures to reduce false positives and accelerate detection engineering response time. By correlating alerts, packets, and context into structured, comprehensive evidence, Corelight enhances visibility, analytics, and investigation speed while integrating seamlessly with existing SIEM, XDR, and SOAR tools.

Corelight Open NDR Platform Pricing

Corelight Open NDR Platform Product Images

Prioritize threats at a glance
Prioritize threats at a glance
Simplify investigations
Simplify investigations
Actionable next-step guidance
Actionable next-step guidance

Overall experience with Corelight Open NDR Platform

Manager of IT Services
30B + USD, IT Services
FAVORABLE

“Corelight's data and evidence is the real hero ”

5.0
Feb 12, 2026
It's been a breath of fresh air compared to the "black box" AI tools that dominate the NDR market. Most tools give you a high-level alert and then leave you to guess what actually happened. Corelight gives you evidence first. It is a large data volume, but once we turned on our ingest and got Zeek logs flowing into our SIEM, the speed of our investigations doubled. It's an impactful pro tool that doesn't hold your hand, but doesn't lie to you.
IT Security & Risk Management Associate
50M - 250M USD, Miscellaneous
CRITICAL

“Challenges With Centralized Management In Multi-Environment Deployments Of Sensor Networks”

3.0
Dec 18, 2025
I feel this vendor could be better at listening to and working with customers to provide product improvement in a timely manner

About Company

Company Description

Updated 12th December 2024

Corelight is a company that primarily focuses on network security. Its objective is to transform network and cloud data into detailed evidence to help counter ever-evolving cyber threats. The company offers an open Network Detection and Response (NDR) platform that provides a comprehensive, correlated view of the network, granting unmatched visibility to users. With the advantage of swift investigation, expert-like cyber threat hunting and potential attack disruption capabilities, Corelight targets to enhance cybersecurity preparedness. It offers both on-premise and cloud-based sensors capable of capturing standard industry telemetry and insights that align with pre-existing user tools and processes. Clients of Corelight span diverse sectors, including large scale businesses, government agencies and research institutions.

Company Details

Updated 12th August 2025
Company type
Private
Year Founded
2016
Head office location
San Francisco, United States
Number of employees
201 - 500
Website
https://www.corelight.com

Do You Manage Peer Insights at Corelight?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Top Corelight Open NDR Platform Alternatives

Logo of Darktrace / NETWORK
1. Darktrace / NETWORK
4.8
(620 Ratings)
Logo of Vectra AI Platform
2. Vectra AI Platform
4.8
(470 Ratings)
Logo of RevealX
3. RevealX
4.7
(260 Ratings)
View All Alternatives

Peer Discussions

Corelight Open NDR Platform Reviews and Ratings

4.8

(129 Ratings)

Rating Distribution

5 Star
81%
4 Star
19%
3 Star
1%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.6

Integration & Deployment

4.7

Service & Support

4.9

Product Capabilities

4.7

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • Manager of IT Services
    10B+ USD
    IT Services
    Review Source

    Corelight's data and evidence is the real hero

    5.0
    Feb 12, 2026
    It's been a breath of fresh air compared to the "black box" AI tools that dominate the NDR market. Most tools give you a high-level alert and then leave you to guess what actually happened. Corelight gives you evidence first. It is a large data volume, but once we turned on our ingest and got Zeek logs flowing into our SIEM, the speed of our investigations doubled. It's an impactful pro tool that doesn't hold your hand, but doesn't lie to you.
  • Manager, IT Security and Risk Management
    Gov't/PS/Ed
    Government
    Review Source

    Death of NDR is greatly exaggerated

    5.0
    Jan 14, 2026
    Corelight have been great and engaged with us from initial deployment stages through to ongoing maintenance in production. Product gets updated frequently with new functionality that is genuinely useful capability additions.
  • Engineering Manager
    50M-1B USD
    IT Services
    Review Source

    Excellent customer support and GUI makes administration simple

    5.0
    Jan 14, 2026
    Corelight staff have been friendly, knowledgeable, and prompt about providing support whenever we have asked, which has occurred on a range of topics over the course of the last year. I have been impressed with their level of responsiveness compared to other vendors, and I have not had a single negative interaction with Corelight even while troubleshooting product problems or issues, which says a lot about their staff's professionalism and courtesy.
  • IT Security & Risk Management Associate
    10B+ USD
    Software
    Review Source

    Corelight Offers Efficient Support and Valuable Insights But Hardware Issues Noted

    5.0
    Dec 17, 2025
    Corelight is easy to work with. They respond to emails quickly, often within minutes of engaging them. Their team is knowledgeable about their product and have been very helpful in getting a deployment planned out and designed. This is the second time I've worked with Zeek, Suricata, and Corelight, and both experiences have been good.
  • IT Security & Risk Management Associate
    <50M USD
    Software
    Review Source

    Corelight’s Knowledgeable Team Enhances Success Despite Complex Suricata Policy Tuning

    5.0
    Dec 2, 2025
    The support team and onboarding teams were/are very responsive and intelligent. Our Corelight TAM is awesome and knowledgeable, and helps us get what we want to get done ... done.
...
Showing Result 1-5 of 131

Recommended Gartner Insights

  • Critical Capabilities for Network Detection and Response
  • Magic Quadrant for Network Detection and Response
Powered by Google TranslateThis service may contain translations provided by Google. Google disclaims all warranties related to the translations, express or implied, including any warranties of accuracy, reliability, and any implied warranties of merchantability, fitness for a particular purpose and noninfringement. Gartner's use of this provider is for operational purposes and does not constitute an endorsement of its products or services.

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.

User Sentiment About Corelight Open NDR Platform
Reviewer Insights for: Corelight Open NDR Platform
Performance of Corelight Open NDR Platform Across Market Features

Corelight Open NDR Platform Likes & Dislikes

Like

The data fidelity is unmatched. The fact that it is built on Zeek and Suricata means I can see exactly why a detection fired. I'm a big fan of the Smart Pcap feature, being able to pull only the relevant packets for a specific flow without wading through terabytes of noise, it's been a massive time saver for my team. Also, the ability to write custom Zeek scripts to hunt for very specific TTPs in our environment gives us a level of flexibility that you just don't get with other platforms.

Like

FleetManager

Like

1) the technical support we got from them to deliver against our sometimes weird use cases. Rapid response and genuine engagement - it felt like engaging with like-minded techies that thrive on problem solving rather than a corporate entity. 2) expanding functionality - the product is constantly evolving to expand its offer in NDR space. Yes, extras require additional licence but it offers genuine value if you need it....this is not a stale product you just pay renewal fees for each year. 3) Integration with my SIEM (Splunk) - my SOC analysts didn't want another product to pivot into...everything they need is in the raw logs or in the Corelight app. Cuts onboarding time significantly.

Dislike

If you're looking for a flashy interactive GUI where you do all your work, it's not there yet. The console is good for management, but you will also be living in your logs or your SIEM. It definitely requires a level of technical maturity to get the full value, but with the amount of data and capability that's to be expected

Dislike

The lack of having fully centralized operational management in environments with a large number of sensors deployed across multiple environments

Dislike

1) needs additional clarity around machine learning components - models need good data (quality and volume) to work. 2) They need to rapidly deploy an mcp server or equivalent to allow SOC analysts (and other users) to understand and action the data that's being generated. 3) Improve training for new users - it's hard to find anything but I know it exists 4) Formal integration of JA4 fingerprinting and building out of its database for network it's monitoring