encrypted traffic collection
Introducing RDP Inferences
Anthony Kasza | | Alert AA21-131A, Announcements, APT39, APT40, Corelight Labs, Crowbar, DarkSide ransomware, Duo, Emotet, encrypted traffic, encrypted traffic collection, JA3, Matrix ransomware, network detection response, Network Security, network security monitoring, network traffic analysis, network visibility, Palo Alto Networks, RDP, RDPBCGR, Richard Bejtlich, rsa, RSAConference, Vern Paxson, Zeek, Zscaler
By Anthony Kasza, Technical Director, Corelight Corelight recently released a new package, focused on RDP inferences, as part of our Encrypted Traffic Collection. This package runs on Corelight Sensors and provides network ...
Introducing the C2 Collection and RDP inferences
Vince Stoffer | | Announcements, Command And Control, encrypted traffic collection, encryption, Malware, MITRE ATT&CK, network detection response, Network Security, network security monitoring, network traffic analysis, network visibility, Product, RDP, rsa, RSAConference, Zeek
By Vince Stoffer, Senior Director, Product Management, Corelight We’re excited to announce that the Command and Control (C2) Collection is now available with today’s launch of version 21 of the Corelight software ...
Small, fast and easy. Pick any three.
Seth Hall | | AArch64, Announcements, Corelight, encrypted traffic collection, encryption, json, Kafka, Linux, Product, Raspberry Pi, software, Splunk, ssl, Suricata, TCP, TLS, vm, Zeek, ZeekWeek
By Seth Hall, Co-Founder & Chief Evangelist, Corelight Zeek has been the darling of security defenders looking to get deep visibility into network traffic. Over the last two decades, Zeek has become ...
Zeek & Sigma: Fully Compatible for Cross-SIEM Detections
Alex Kirk | | encrypted traffic collection, Joe Sandbox, Microsoft Azure, MISP, NDR, network detection response, Network Security, network traffic analysis, network visibility, partnership, SANS, SIEM, Sigma, SOC, SOC Prime, Yara, Zeek
By Alex Kirk, Corelight Global Principal for Suricata Corelight recently teamed up with SOC Prime, creators of advanced cyber analytics platforms, to add support for the entire Zeek data set into Sigma, ...
The light shines even brighter: Updates to Corelight’s Encrypted Traffic Collection
Vince Stoffer | | agent forwarding, Announcements, Authentication, Chrome, dns, DoH, encrypted traffic, encrypted traffic collection, Firefox, network security monitoring, network traffic analysis, network visibility, reverse tunnel, SSH, Suricata, Zeek
By Vince Stoffer, Senior Director, Product Management, Corelight With Corelight’s latest software release, v19, we are excited to announce the expansion of our Encrypted Traffic Collection (ETC). The ETC was introduced in ...

