Corelight

Corelight

Network detection and response technology provider

Overview

Corelight provides network detection and response (NDR) technology to improve cybersecurity. It collects and analyzes network data through the Open NDR Platform and the Cloud Sensor for AWS, giving customers visibility, aiding threat hunting, and speeding up incident response across on-premise and cloud environments. What sets Corelight apart is its open, partner-friendly approach that lets other security vendors build analytics on top of its technology, with interoperability across major vendors and a cloud-native option for AWS. The goal is to strengthen cyber defense by delivering scalable network visibility and fast detection, growing adoption through direct sales and partnerships that integrate Corelight’s Open NDR technology into other offerings.

About Corelight

Simplify's Rating
Why Corelight is rated
C+
Rated C on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Data & Analytics

Enterprise Software

Cybersecurity

Company Size

201-500

Company Stage

Series E

Total Funding

$309.2M

Headquarters

San Francisco, California

Founded

2013

Get referred to Corelight

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Amanda Berger joined July 27, 2026, strengthening retention and expansion execution.
  • The June 2026 AI Proving Grounds Consortium positions Corelight inside emerging AI SOC standards.
  • Open NDR v29.1 and AWS cloud sensors deepen product breadth across hybrid environments.

What critics are saying

  • CrowdStrike, Microsoft, and Palo Alto Networks compress NDR pricing before 2027.
  • FedRAMP completion delays block federal revenue conversion and extend sales cycles.
  • Zeek-based visibility stays partially commoditized, risking Corelight becoming interchangeable infrastructure.

What makes Corelight unique

  • Corelight converts network traffic into forensic evidence, not generic alert noise.
  • Its June 2026 Open NDR expansion added passive asset classification and network performance monitoring.
  • FedRAMP In Process on June 9, 2026 strengthens federal credibility and procurement access.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$309.2M

Above

Industry Average

Funded Over

5 Rounds

Series E funding typically includes additional rounds after Series D if the company needs more capital. The business is usually stable, and these rounds are typically used for further expansion or to address market challenges.
Series E Funding Comparison
Above Average

Industry standards

$100M
$245M
Stripe
$250M
Reddit
$1.3B
Epic Games
$1.5B
Airbnb

Benefits

Remote Work Options

Flexible Work Hours

Company Equity

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

2%
PR Newswire
Jul 27th, 2026
Corelight appoints Amanda Berger as chief customer officer

Corelight, a cybersecurity firm specialising in network evidence platforms, has appointed Amanda Berger as chief customer officer. Berger brings over 25 years of experience in customer leadership across cybersecurity and SaaS companies. In her new role, Berger will oversee Corelight's customer success organisation, managing the complete customer journey from implementation through expansion. She previously served as chief customer officer at Employ, HackerOne, Lucidworks and RichRelevance, where she developed customer retention and expansion strategies. The appointment follows recent additions to Corelight's leadership team, including cybersecurity veteran Hatem Naguib joining the board and Tenable co-founder Jack Huffard as adviser. The company recently expanded its Open NDR platform to include passive asset classification and network performance monitoring.

Renascence
Jul 27th, 2026
Corelight names Amanda Berger Chief Customer Officer.

Corelight names Amanda Berger Chief Customer Officer. Corelight has appointed Amanda Berger as CCO, elevating post-sale customer experience to board level in a signal that retention is now a revenue priority in enterprise cybersecurity. Renascence Newsdesk What happened. Corelight, a network-detection and response security firm, has appointed Amanda Berger as its new Chief Customer Officer. The announcement marks a deliberate move by the company to elevate post-sale customer experience to the executive level, signalling that customer retention and success are now board-level priorities rather than operational afterthoughts. Berger steps into the role with a remit to oversee the full customer lifecycle - from onboarding and adoption through to long-term retention and advocacy - as Corelight competes in an increasingly crowded cybersecurity market where product differentiation alone is no longer sufficient. Why it matters. The creation or elevation of a Chief Customer Officer role is one of the clearest structural signals a company can send about where it believes competitive advantage now lives. In high-complexity B2B categories such as enterprise security, the buying decision is only the beginning of the relationship; the real value - and the real risk of churn - sits in what happens after contract signature. By installing a CCO at the executive table, Corelight is acknowledging that customer experience is a revenue function, not a support function. From a behavioural economics perspective, this matters because enterprise customers are not purely rational actors. Trust, perceived effort, and the consistency of human touchpoints all shape renewal decisions as powerfully as product performance metrics. A dedicated CCO can design the rituals, cadences and recovery moments that keep customers psychologically anchored to a vendor - reducing the cognitive ease with which a competitor can displace them. The Renascence take. Most commentary on CCO appointments focuses on the individual's credentials. The more important question is whether the organisation has genuinely restructured decision-making authority around the customer, or simply added a title to the org chart without changing how trade-offs get made. The appointment of a CCO is a hypothesis, not an outcome. The real test is whether Berger has budget authority, a seat in product roadmap discussions, and the power to override revenue-quarter thinking when it conflicts with long-term customer health. In its experience, CCOs who report to the CEO and control the full post-sale motion drive measurable NPS and net revenue retention improvements; those who sit beneath a CRO frequently become sophisticated complaint handlers. Corelight's leadership should be asked, publicly, which model they have chosen - because the answer determines whether this hire changes anything at all for their customers. This briefing was written by the Renascence newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage. More in Customer Experience Stay ahead of CX Get the signal, not the noise. The stories shaping customer experience - plus the Journal and Experience Loom - in your inbox.

Weirdware
Jul 24th, 2026
Reconsider legacy tech and remote-access security in the AI age.

Reconsider legacy tech and remote-access security in the AI age. Corelight, Dropzone AI, Scythe, SimSpace, and Sondera launch AI proving ground. 24th July 2026 Five AI companies are teaming up to boost enterprise trust in AI agents via a new consortium. Secops-focused Dropzone AI said the new AI Proving Ground Consortium (AIPGC) will rigorously train, test, and prove agentic AI defences in production-like environments. Edward Wu, founder and CEO of Dropzone AI, said enterprises need to know they can trust agentic AI. As AI takes on a bigger role, organisations need confidence on how these systems perform in real environments. "The future of the SOC is multiple AI agents working together, alongside human analysts, across investigations, threat hunting, intelligence and response," Wu said. "This consortium can help establish the benchmarks and standards organisations need to confidently adopt AI and accelerate its full operational impact on security." As a result, the first virtual event from the venture between founders Dropzone AI, Corelight, Scythe, SimSpace and Sondera was held mid-June. Peter Lee, CEO of testing platform SimSpace, the lead organiser, said AI weaponisation is a bigger problem than any organisation can handle alone. "That's why we're forming the AIPGC to pool our collective ideas and cyber expertise," Lee confirmed. "AI is transforming cybersecurity. Organisations need a way to rigorously train, test, and validate AI agents together with human cyber operators." AI agents in secops and services. Dropzone AI's agentic secops offering targets managed security services providers (MSSPs). As a result, it has rolled out AI SOC Analyst, enabling autonomous investigation of more alerts and AI Threat Hunter, which runs prebuilt or custom 'hunt' packs for SIEM, EDR, and cloud. In addition, it offers AI Threat Intel Analyst, which analyses and designs responses for the AI Threat Hunter agent. "SimSpace research found that nearly 80% of security leaders report high confidence in their AI defences," the announcement said. "Measured readiness scores can be as low as 30% before repeated simulation exercises." Additionally, many organisations rely on legacy preparation strategies, like tabletop exercises and certification courses, it said.

Help Net Security
Mar 18th, 2026
Corelight's Agentic Triage turns SOC alerts into evidence-backed investigations.

Corelight's Agentic Triage turns SOC alerts into evidence-backed investigations. Corelight has introduced a new set of agentic AI capabilities aimed at helping security operations centers (SOCs) cut down on repetitive, time-consuming tasks. The updates are designed to boost analyst efficiency, speed up response times, and build trust through greater transparency. The release includes Agentic Triage to streamline SOC workflows, a new suite of machine learning models that turn encrypted traffic blind spots into actionable evidence, and expanded integrations "By pairing the industry's highest-fidelity network telemetry from Corelight with an expert-governed AI agent, we are giving security teams the evidence they need to trust, verify, and act on AI-generated insights," said Vijit Nair, Corelight vice president of product. "Only Corelight delivers true agentic AI triage in NDR, uniquely transforming overwhelming alert queues into verified, defensible investigations by applying expert playbooks to industry-leading network evidence with AI reasoning, drastically reducing time-to-triage and equipping analysts with definitive answers." Accelerating SOC workflow through agentic intelligence. SOCs are under pressure as adversaries actively leverage generative AI to automate reconnaissance and accelerate attacks, while most triage processes remain manual, repetitive, and highly variable across analysts. Corelight Agentic Triage is a category-first automated investigation capability that helps security teams move from high-volume alert noise to evidence-backed containment, making triage up to 10x faster. Powered by a modern GenAI agent architecture and driven by expert-written investigative playbooks, Agentic Triage automatically investigates the highest-risk entities in a customer's environment on a daily basis. Instead of requiring analysts to manually review hundreds of individual alerts, the Corelight Lux agent consolidates signals into entity-centric investigations, applies structured investigative logic, and delivers a single, evidence-backed triage verdict, complete with transparent reasoning a human analyst can inspect and verify. Unlike proprietary systems that hide the details used to inform AI decision-making, Corelight Agentic Triage exposes every playbook step, every query run, and every piece of evidence used to reach a conclusion. This "show-your-work" approach is purpose-built for enterprise SOCs that require AI to be accountable, reviewable, and defensible during audits and incident response reviews. Connecting to and empowering the ai-enabled ecosystem. Once analysts have identified the highest-risk entities and are ready to take action, they want to contain threats immediately without having to pivot to another system. Corelight ingests real-time identity data to enrich and complement the network evidence and correlate insights about problematic entities connected to the network. Now that analysts can connect the "who" to the "what" that is happening on the network, they can use the integrations with Microsoft Azure AD/Entra and CrowdStrike to trigger one-click actions such as universal logout and password resets without pivoting to a separate tool. This ability to take response actions directly on compromised identities builds on Corelight's ability to directly quarantine endpoints and trigger firewall block actions. In addition, Corelight has released a new integration with CrowdStrike's Charlotte AI and Agentic Response Collaboration, seamlessly working with other AI agents across the security stack to maximize the value of network data, providing critical context for investigations no matter where they occur. The integration creates a CrowdStike Fusion workflow that allows Charlotte AI to automatically pull Corelight ground truth data to help an analyst resolve an alert by validating host behavior against network reality. "The question facing every CISO today is not whether to adopt AI in the SOC - but rather how quickly and how comprehensively," said Andrew Braunberg, principal analyst at Omdia. "Adding to the urgency is the weaponization of generative models by adversaries to automate reconnaissance, accelerate attacks, and evade detection. Defenders need AI that can accelerate response, and critically, that shows its work. To build trust in these solutions, explainability isn't a nice-to-have; it's a requirement, particularly in regulated environments." Detecting multi-stage intrusions with advanced ML everywhere. Indisputable evidence and robust detections are the foundation for any AI capability to be successfully integrated into today's modern SOC. To support the advancement of AI in the SOC, Corelight is also introducing an expansion of its advanced machine learning and behavioral detections with a new suite of statistical models designed to detect evasive, post-exploitation techniques, including tunneling anomalies and VPN anomalies, without requiring decryption. Sophisticated threat actors are looking for the dark corners of target networks to exploit, increasingly tunneling attacks in encrypted sessions to evade detection and hide their true intent. By analyzing the statistical "shape" and behavioral metadata of traffic, Corelight is able to transform encrypted blind spots into high-fidelity evidence. This allows security teams to better identify covert command and control (C2) channels and lateral movement, even in environments where traditional inspection is impossible. Corelight's new ML models detect evasive threats that traditional signatures miss by analyzing behavioral patterns across the network, flagging unauthorized VPNs, identifying uncommon tunneling activity at the subnet level, and catching credential theft techniques like DCSync and NTDS.dit dumps before attackers can pivot. The platform has also expanded its brute force detection surface, correlating both low-and-slow and high-volume credential attacks across critical vectors including Kerberos, RDP, SMB, and SSH. Together, these models give security teams high-fidelity visibility into post-exploitation activity without requiring decryption. More about

PR Newswire
Mar 18th, 2026
Corelight launches agentic AI suite to accelerate SOC triage 10x faster with transparent evidence

Corelight has launched Agentic Triage, what it calls category-first agentic AI capabilities for security operations centres. The network detection and response company claims the system can make triage up to 10 times faster by automating repetitive investigative tasks. The platform uses AI agents powered by expert-written playbooks to automatically investigate high-risk entities, consolidating alerts into single, evidence-backed verdicts. Unlike proprietary systems, Corelight exposes every playbook step and piece of evidence used to reach conclusions, designed for enterprise environments requiring accountable AI. Corelight has also released integrations with Microsoft Azure AD/Entra and CrowdStrike, allowing analysts to trigger one-click containment actions like universal logout directly from the platform. Additionally, the company introduced new machine learning models to detect evasive techniques in encrypted traffic without requiring decryption.

Recently Posted Jobs

Sign up to get curated job recommendations

Corelight is Hiring for 10 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →