InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

Suricata + Zeek: How it Works

Presented by

Corelight

About this talk

Put defenders on top with alerts integrated into evidence. Corelight delivers the foundation next-level incident response by integrating the open source powerhouses Zeek and Suricata. With Suricata alerts embedded directly into Zeek logs, analysts can see linked activity across a host of vital protocols including as DNS and HTTP. This helps them make faster decisions, and see patterns of activity across your whole network. Both Suricata and Zeek let you create solutions that fit your environment through rapid customization. You can load any open source ruleset you want, then feed the alerts into scripts you’ve written for event handling. This leads to real security impact, like when it allowed our community to respond to Curveball in just one day.
Corelight

Corelight

2350 subscribers39 talks
Corelight transforms network and cloud activity into evidence
Corelight transforms network and cloud activity into evidence so that data-first defenders can stay ahead of ever-changing attacks. Delivered by our open NDR platform, Corelight’s comprehensive, correlated evidence gives you unparalleled visibility into your network. This evidence allows you to unlock new analytics, investigate faster, hunt like an expert, and even disrupt future attacks. Our on-prem and cloud sensors go anywhere to capture structured, industry-standard telemetry and insights that work with the tools and processes you already use. Corelight’s global customers include Fortune 500 companies, major government agencies, and research universities.
Related topics