# Corelight

*/Startups/Corelight*

## Startup Overview

This platform converts raw network traffic into structured Zeek evidence. Security operations centers rely on this system to process massive volumes of packet data, extracting actionable context from opaque data streams. Instead of storing petabytes of unsearchable packets, incident responders access an organized telemetry layer designed for immediate investigation.

Unlike closed-ecosystem platforms like ExtraHop, Vectra AI, and Darktrace that rely on black-box anomaly detection, or legacy full packet capture systems that drown analysts in raw noise, this architecture runs entirely on open-source standards. It delivers transparent, query-ready network data rather than proprietary alerts. This design optimizes workflows for data-centric threat hunting, giving security teams the exact evidence required to trace lateral movement and neutralize active network threats.

## Startup Founding Hypothesis

**Approach**: that converts raw network traffic into structured Zeek evidence
**Competitors**:
- [ExtraHop](/Competitors/ExtraHop)
- [Vectra AI](/Competitors/Vectra_AI)
- [Darktrace](/Competitors/Darktrace)
- [legacy full packet capture](/Competitors/legacy_full_packet_capture)
**Differentiator2x2**: built on open-source standards and optimized for data-centric threat hunting

## Startup Solution Coordinate

**Solution**: [Zeek Evidence Platform](/Software/Zeek_Evidence_Platform)

## Startup Position2x2

```mermaid
quadrantChart
    title Position: Network Traffic Analysis
    x-axis Proprietary Ecosystem --> Open Standards
    y-axis Alert-Centric Black Box --> Structured Threat Hunting
    quadrant-1 Evidence Driven
    quadrant-2 Proprietary NDR
    quadrant-3 AI Monoliths
    quadrant-4 Raw Data Stores
    Corelight: [0.85, 0.85]
    Legacy PCAP: [0.85, 0.15]
    ExtraHop: [0.35, 0.65]
    Vectra AI: [0.25, 0.35]
    Darktrace: [0.15, 0.15]
```

## Startup Offer

**Proof**:
- Targeting comprehensive east-west traffic visibility for enterprise data centers.
- Aiming to reduce threat hunting query execution from hours to seconds.
- Designed to eliminate raw packet storage overhead by converting traffic to structured metadata.
**Tiers**:
- Name: Gigabit Edge · Price: ~$800–$1,500/mo per Gbps · Inclusions: Continuous raw network traffic parsing into structured Zeek logs, designed for branch offices or edge gateways up to 1 Gbps throughput.
- Name: Datacenter Core · Price: ~$3,000–$6,000/mo per 10 Gbps · Inclusions: High-volume traffic parsing for core switches, including custom Zeek scripting support and automated SIEM ingestion formatting.
- Name: Cloud Fleet · Price: ~$15,000–$30,000/mo · Inclusions: Unmetered traffic parsing across up to 50 distributed cloud VPCs, featuring encrypted traffic inference and dedicated deployment architecture support.
**Guarantee**: Guarantees complete protocol parsing at the provisioned throughput without packet drop; if a sensor drops traffic due to system overload at rated speeds, the affected month of service is credited.
**Business Function**: ProvideService
**Objection Handlers**:
- Objection: We already have raw packet capture. Rebuttal: Corelight transforms packets into indexable, structured evidence, saving storage costs and dramatically accelerating search queries.
- Objection: We can deploy open-source Zeek ourselves for free. Rebuttal: Corelight delivers a managed, pre-optimized Zeek deployment that requires zero internal engineering overhead to scale or maintain.
- Objection: Deploying network taps will disrupt production traffic. Rebuttal: The sensors run passively out-of-band via span ports or packet brokers, ensuring zero impact on inline routing.
**Pricing Architecture**: UsageMeter
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Clinical and technical, prioritizing forensic exactness over marketing appeal
**Tagline**: Converts raw network traffic into structured threat hunting evidence
**Icon Concept**: wire
**Palette Intent**: electric-signal
**Visual Identity**: Deep terminal black and phosphorescent green emphasize digital forensic precision, supported by strict monospace typography that mirrors command-line evidence logs.
**Archetype Reference**: the-sage

## Startup Buyer Chain

**Chain**: Vendor → CISO / VP of Security Operations → SOC Analysts / Threat Hunters
**Gtm Motion**: Acquires mature enterprise security teams by targeting existing open-source Zeek deployments that require enterprise management and performance scaling. Expands account value by deploying additional network sensors across cloud environments and branch offices to increase total inspected traffic volume.
**Agent Channel**: Designed to list in SOAR tool registries and automated threat hunting API catalogs, allowing autonomous security agents to discover and query structured network traffic evidence during incident triage.
**Primary Channel**: Open-source community conversion via Zeek-focused technical conferences and targeted search capture for 'enterprise Zeek support' and 'scalable full packet capture alternatives'.

## Startup Customer Journey

```mermaid
flowchart LR; A[Zeek Conference] --> B[Trial Sandbox]; B --> C[Edge Sensor]; C --> D[SIEM Platform]; D --> E[Cloud Fleet]; E --> F[Case Study Publication];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day passive span port deployment at a single edge gateway aiming to validate complete protocol parsing and successful log ingestion into the existing SIEM.
- 30-day datacenter core tap trial at 10 Gbps throughput designed to prove a massive reduction in telemetry volume compared to raw packet capture while retaining critical forensic evidence.
**Target Metrics**:
- Target: 80 percent reduction in network telemetry storage costs by replacing raw packet capture with structured metadata.
- Target: Under 5 seconds average execution time for complex threat hunting queries.
- Target: Zero packet drop rate at provisioned multi-gigabit throughput levels.
- Target: Under 2 hours deployment time from passive tap connection to active SIEM ingestion.
**Target Case Studies**:
- Target: A large financial institution operating a centralized datacenter. Transformation: Shifting from expensive raw packet capture arrays to structured Zeek logs, allowing them to retain 90 days of searchable metadata within existing SIEM storage limits.
- Target: A distributed retail enterprise with numerous branch offices. Transformation: Gaining centralized east-west traffic visibility across edge networks without deploying internal engineering teams to maintain open-source sensors.
- Target: A cloud-native service provider. Transformation: Utilizing encrypted traffic inference across multiple distributed VPCs to identify lateral movement blind spots without decrypting payloads.
**Testimonial Targets**:
- Target CISO: Expresses confidence in achieving comprehensive east-west network visibility without exceeding SIEM storage budgets.
- Target Lead Threat Hunter: Highlights the relief of escaping raw PCAP analysis to query clean, structured Zeek logs instantly.
- Target Network Engineering Director: Validates the zero-impact, out-of-band deployment that removes the burden of managing internal open-source deployments.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Black-box AI competitors convince security leaders that automated detection replaces manual data-centric threat hunting, destroying the demand for structured Zeek evidence. · Mitigation Status: unmitigated
- Severity: high · Description: Ubiquitous adoption of TLS 1.3 and encrypted client hello blinds passive network sensors, severely reducing the actionable metadata Corelight can extract. · Mitigation Status: in-progress
- Severity: high · Description: Major cloud providers introduce native structured network evidence logging that directly undercuts the deployment of third-party Corelight sensors in cloud environments. · Mitigation Status: unmitigated
- Severity: moderate · Description: The open-source Zeek project community governance fractures or diverges from enterprise needs, threatening the platform's foundational dependency. · Mitigation Status: mitigated

## Startup Competitors

- [ExtraHop](/Competitors/ExtraHop) — NDR Platform
- [Vectra AI](/Competitors/Vectra_AI) — Threat Detection
- [Darktrace](/Competitors/Darktrace) — Network Security
- [Legacy Full Packet Capture](/Competitors/Legacy_Full_Packet_Capture) — Status Quo
- [RSA NetWitness](/Competitors/RSA_NetWitness) — Incumbent NDR

## Startup Solution Stack

- [Network Evidence Service](/Services/Network_Evidence_Service) — Service-as-Software
- [Traffic Parsing Agent](/Agents/Traffic_Parsing_Agent) — Agent
- [Protocol Analysis Worker](/Agents/Protocol_Analysis_Worker) — Agent
- [Zeek Processing Engine](/Software/Zeek_Processing_Engine) — Software
- [Packet Capture API](/Software/Packet_Capture_API) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the forensic expert who provides answers in seconds, not the analyst waiting on packet downloads
- **Want**: to turn raw network traffic into searchable evidence without massive storage costs
- **Identity**: the SOC Lead at a global enterprise datacenter
**Plan**:
- Step: Deploy · Detail: Install passive sensors out-of-band via span ports or packet brokers with zero production disruption.
- Step: Audit · Detail: Inspect the automated Zeek metadata stream to ensure every protocol is correctly parsed and indexed.
- Step: Search · Detail: Query structured evidence in your SIEM to resolve threats in seconds instead of hours.
**Guide**:
- **Empathy**: You shouldn't still be manually carving PCAPs just to find a single handshake. ExtraHop wasn't built to provide the long-term structured evidence required for modern threat hunting.
**Problem**:
- **Villain**: packet-capture bloat
- **External**: Sifting through terabytes of PCAPs in ExtraHop or legacy full-packet capture systems delays incident response by hours while taxing storage budgets.
- **Internal**: You feel blind to east-west traffic because the data is too heavy to actually use.
- **Philosophical**: Why should security teams accept data-scarcity due to storage-costs when metadata can prove exactly what happened?
**Success**: Every network interaction is logged as structured, searchable metadata. You identify lateral movement and data exfiltration in seconds, with months of forensic history stored at a fraction of the cost of raw packets.
**One Liner**: What if your network traffic was as searchable as your logs? Corelight converts raw traffic into structured Zeek evidence, accelerating threat hunting from hours to seconds.
**Positioning**:
- **So That**: transform wire traffic into searchable metadata without packet storage overhead
- **Unlike**: legacy full packet capture
- **For Whom**: the SOC Lead at a global enterprise
- **Category**: Network Detection and Response
**Call To Action**:
- **Direct**: Provision a sensor
- **Transitional**: View Zeek log schema
**Failure Stakes**:
- Dwell times increase while analysts wait for packet reassembly.
- Storage costs for raw packets force you to delete critical evidence.
- Blind spots in east-west traffic hide lateral movement.
**Transformation**:
- **To**: the enterprise's lead threat hunter
- **From**: a packet-miner stuck in slow forensic downloads
**Controlling Idea**: Network evidence must be structured and searchable to be useful for defense.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: What if your network traffic was as searchable as your logs? Corelight converts raw traffic into structured Zeek evidence, accelerating threat hunting from hours to seconds.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 64d1e298d5c71fc3

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Network Detection and Response for the SOC Lead at a global enterprise. Unlike legacy full packet capture — transform wire traffic into searchable metadata without packet storage overhead.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: 191e870184be95bd

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Sifting through terabytes of PCAPs in ExtraHop or legacy full-packet capture systems delays incident response by hours while taxing storage budgets.
Solution: What if your network traffic was as searchable as your logs? Corelight converts raw traffic into structured Zeek evidence, accelerating threat hunting from hours to seconds.
Customer: the SOC Lead at a global enterprise
Unlike: legacy full packet capture
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 8281cd393c6cfd7f

## Startup Token M E D D P I C C

**Pain**: Sifting through terabytes of PCAPs in ExtraHop or legacy full-packet capture systems delays incident response by hours while taxing storage budgets.
**Metrics**: Target: Every network interaction is logged as structured, searchable metadata. You identify lateral movement and data exfiltration in seconds, with months of forensic history stored at a fraction of the cost of raw packets.
**Rendered**: Pain: Sifting through terabytes of PCAPs in ExtraHop or legacy full-packet capture systems delays incident response by hours while taxing storage budgets.
Economic buyer: CISO / VP of Security Operations
Metrics: Target: Every network interaction is logged as structured, searchable metadata. You identify lateral movement and data exfiltration in seconds, with months of forensic history stored at a fraction of the cost of raw packets.
Competition: legacy full packet capture
**Mechanism**: spine-derived-v1
**Competition**: legacy full packet capture
**Economic Buyer**: CISO / VP of Security Operations
**Vocab Fingerprint**: 3883641db8c22328

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Network Detection and Response for the SOC Lead at a global enterprise

the SOC Lead at a global enterprise — Sifting through terabytes of PCAPs in ExtraHop or legacy full-packet capture systems delays incident response by hours while taxing storage budgets. What if your network traffic was as searchable as your logs? Corelight converts raw traffic into structured Zeek evidence, accelerating threat hunting from hours to seconds.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 9bbbfb45571e3c1d

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Network Detection and Response. What if your network traffic was as searchable as your logs? Corelight converts raw traffic into structured Zeek evidence, accelerating threat hunting from hours to seconds. Serves the SOC Lead at a global enterprise.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: e385cda485f4442e

## Neighborhood

### Candidate solutions

- [Calculate Grower Liquidations](/Problems/Calculate_Grower_Liquidations) — candidate solution for · Problems

### Composed of

- [Packet Capture API](/Software/Packet_Capture_API) — composes · Software
- [Network Evidence Service](/Services/Network_Evidence_Service) — composes · Services
- [Traffic Parsing Agent](/Agents/Traffic_Parsing_Agent) — composes · Agents
- [Protocol Analysis Worker](/Agents/Protocol_Analysis_Worker) — composes · Agents
- [Zeek Processing Engine](/Software/Zeek_Processing_Engine) — composes · Software

### Embodies

- [Software](/Theses/Software) — embodies · Theses

### What it offers

- [Zeek Evidence Platform](/Software/Zeek_Evidence_Platform) — offers · Software

### Competitors

- [Legacy Full Packet Capture](/Competitors/Legacy_Full_Packet_Capture) — competes with · Competitors
- [RSA NetWitness](/Competitors/RSA_NetWitness) — competes with · Competitors
- [Vectra AI](/Competitors/Vectra_AI) — competes with · Competitors
- [Darktrace](/Competitors/Darktrace) — competes with · Competitors
- [ExtraHop](/Competitors/ExtraHop) — competes with · Competitors

### Similar Startups

- [Whispirtual](/Startups/Whispirtual) — similar · Startups
- [Hopporosity](/Startups/Hopporosity) — similar · Startups
- [Gatherstar](/Startups/Gatherstar) — similar · Startups
- [Burdoom](/Startups/Burdoom) — similar · Startups
- [Mohex](/Startups/Mohex) — similar · Startups
- [Flarestorm](/Startups/Flarestorm) — similar · Startups
- [Dropzone Security](/Startups/Dropzone_Security) — similar · Startups
- [Triageridge](/Startups/Triageridge) — similar · Startups
- [Gatewayneedle](/Startups/Gatewayneedle) — similar · Startups
- [Zoneframe](/Startups/Zoneframe) — similar · Startups
- [Aniquad](/Startups/Aniquad) — similar · Startups
- [Activefire](/Startups/Activefire) — similar · Startups
- [Evequence](/Startups/Evequence) — similar · Startups
- [Quafac](/Startups/Quafac) — similar · Startups
- [Cyberlume](/Startups/Cyberlume) — similar · Startups
- [Sensoratelier](/Startups/Sensoratelier) — similar · Startups
- [Integratedridge](/Startups/Integratedridge) — similar · Startups
- [Outlystal](/Startups/Outlystal) — similar · Startups
- [Blazecrest](/Startups/Blazecrest) — similar · Startups
- [Intaff](/Startups/Intaff) — similar · Startups
