In this Q&A, we ask Matt Ellison, Director of Sales Engineering, EMEA about Corelight’s proposition, evolution and value to the channel.
Corelight, the leader in open network detection and response (NDR), gives organisations a better way to detect early warning signs of a breach (and actively hunt for threats), empowering SOC analysts to prioritise alerts and take action to contain and eliminate threats before they can have a significant impact.
Its NDR platform and natively integrated Suricata intrusion detection software (IDS) are complementary, add-on solutions to existing endpoint detection and response (EDR) tools, giving system integrators and MSSPs the opportunity to add value for their EDR customers and boost revenue through sales and additional service revenue.
Corelight says its NDR platform has particular value for partners because it is built on open source technology and is backed by strong industry alliances. This allows Corelight to deliver industry-leading technologies like Zeek – the standard for network security monitoring – and integrate more capabilities both upstream, e.g. threat intelligence feeds, and downstream, e.g. analytics vendors.
This, it says, is preferable to black box NDR, which serves up alerts but provides no information on how decisions are reached.
Technology Reseller (TR): Please could you provide some background on the genesis of Corelight and the problem it addressed.
Matt Ellison (ME): Our story starts more than 25 years ago with our co-founder Dr. Vern Paxson, who was working at the Lawrence Berkeley National Laboratory. Vern needed to better understand what was happening on the lab’s networks, so he created an open source project, now called Zeek, to provide detailed information about network activity.
Cofounder Dr. Robin Sommer joined the project, now based out of the International Computer Science Institute in Berkeley, in 2001. A third co-founder Seth Hall began contributing in 2007.
Under Robin’s leadership, the project received millions of dollars of financial support from the US National Science Foundation (NSF), which was instrumental in turning a powerful but boutique system into an industrial-strength platform. The US Department of Energy also provided financial support during this period.
By 2013, the platform’s ability to provide evidence in the form of network data logs had become the gold standard for understanding network activity.
To support the Zeek project, Vern, Robin and Seth founded a company – now named Corelight – with a business model to provide services to make it easier for companies to leverage Zeek. By 2015 it had become clear that people needed more than a service – they demanded a fully integrated system that truly leveraged the design pattern built by the Zeek community.
The company was incorporated in 2016 and the Corelight Sensor was born. Today, Zeek is the world’s leading platform for network security monitoring, and Corelight continues to be its steward.
Our offerings now include rich insights not only from Zeek, but also Suricata; we’ve created our own proprietary technologies for VPN, encrypted collections, packet capture and more; our sensors now address virtual, software, cloud and physical environments; and we’ve added machine learning and intuitive scalable search to the mix.
Serving large enterprises and government agencies in more than fifteen countries, we help organisations translate network and cloud activity into evidence that they can use to proactively hunt for threats, quickly investigate cyber incidents, gain visibility into their networks and leverage analytics powered by machine learning.
TR: What’s different about Corelight’s approach and why is this relevant now?
ME: Corelight provides a Network Detection and Response (NDR) platform, differentiated by its use of open source technologies such as Zeek and Suricata. This is a tremendous advantage in that new insights and evidence are continually being fed into the platform, which means that the evidence/data we provide is more comprehensive than other offerings. It’s also linked to other data for context and unique insight – for example encrypted traffic.
We also offer arguably the broadest range of detection techniques, including machine learning, behavioural models, signatures and queries, from a single platform delivering network security monitoring, intrusion detection (IDS), packet capture and investigation/threat hunting. Corelight’s open source heritage means it integrates seamlessly with existing customer toolsets such as XDR, SIEM and SOAR platforms.
In fact, customer experience is key – Corelight has an industry leading NPS score and net/gross retention, driven by proactive support capabilities including the assignment of a technical account manager to every customer.
TR: What is your typical customer profile and your route to market?
ME: Our typical customers are larger enterprises that already have a Security Operations Centre (SOC) for threat detection and response and core technologies such as endpoint protection and SIEM in place.
While cybersecurity is relevant to all vertical markets, we tend to sell more to customers in the finance, critical infrastructure, government and high technology sectors. Corelight has a strong base of resellers around the world that help us to identify opportunities, assist with the sales process and ultimately support the customer.
TR: What were the challenges Corelight faced in gaining a foothold in the market and how did you overcome them?
ME: Outside the classic start-up challenges of scale, funding and focus, our primary challenge initially was driving market awareness and acceptance. NDR was not a clearly defined cybersecurity category until a few years ago and it was difficult for customers to secure budget or easily understand where we fit in their infrastructure.
This has changed more recently thanks to Gartner’s SOC Triad, which clearly shows NDR, EDR and SIEM as core technologies. Our own positioning of the platform – as one that is based on the design patterns of elite defenders – has also helped.
Another core challenge is the sheer number of potential use cases that the platform has – dozens, if not hundreds. That’s good for a customer once they’ve installed it, but can be tricky to market.
We have addressed this in the past 18 months with clearer messaging that highlights the value of an evidence-based approach to threat detection and the four critical value pillars: visibility, detection/analytics, investigations and threat hunting.
TR: How has Corelight grown and where are you having most success?
ME: We continue to have most success in verticals that are highly risk-averse and run mission-critical applications, including federal government, critical infrastructure, finance, healthcare and technology companies.
Our growth over the past few years has been tremendous, resulting in multiple funding rounds and strong interest from the investment community. Corelight had significant growth even through the pandemic years and this has been fuelled not only by new logo acquisition but also by customer expansions and renewals.
TR: How has your solution evolved since it was launched and how do you expect it to develop in the future?
ME: The company is not yet 10 years old but has already evolved the platform significantly. We’ve integrated open source Suricata IDS technology, so that alerts and detections are immediately contextualised and prioritised, and we’ve enhanced the platform with Smart PCAP technology, which allows customers to retrieve only the packets they need, versus full packet capture.
Corelight has also launched a SaaS-based offering, as well as delivering multiple options for non-SaaS, across physical, virtual and cloud. Looking ahead, we will continue to invest in areas that expand what we can detect and how – particularly in the field of AI and machine learning – and we’ll look to increase visibility further into the cloud and IoT/OT environments, as organisations double down on these technologies to drive a new wave of digital transformation.
TR: How do you expect the cybersecurity market to evolve?
ME: The biggest trend right now is consolidation. Customers have too many tools and are finding they lack a single source of truth when it comes to data/evidence. This is a challenge from a skills perspective.
With SOC analysts in high demand and teams stretched to the limit, organisations are finding that they can’t keep their SecOps practitioners trained on all the tools at their disposal. Also, having more tools does not necessarily lead to better coverage; organisations are still finding gaps in their security.
Another emerging trend is the growing popularity of threat hunting. More organisations are getting proactive about detection so they can enhance the cyber-resilience of their infrastructure. They’ll need every tool and tactic at their disposal, as the bad guys keep innovating and attack surfaces continue to expand. IoT and OT security is a big emerging area, with the network edge a prime candidate for attack.


Be First to Comment