
The typical implementation process for Open NDR software involves these steps:
Telemetry Selection: Choose the right telemetry sources using Zeek, a standard in network security monitoring.
Alert Correlation: Fuse alerts and packets with context to establish a reliable source of truth.
Open NDR can be customized to fit specific business needs. Here's how:
Telemetry Selection: Open NDR uses Zeek, the gold standard in open-source network security monitoring. It allows you to select the telemetry that matters most to your business.
Integration: The platform integrates easily with existing SIEM, XDR, and SOAR solutions, so you can customize how it fits into your current security infrastructure.
Open Core Approach: Corelight uses an open core approach, providing flexibility and customization options.
Open NDR by Corelight offers a variety of training and support options to help new users effectively deploy and manage the platform. These include:
Corelight Academy – Online self-paced courses covering Open NDR fundamentals and advanced use cases.
Instructor-led Training – Live, hands-on sessions conducted by Corelight security experts.
Workshops & Webinars – Interactive learning sessions focusing on best practices, use cases, and threat detection strategies.
Technical Documentation & Knowledge Base – Extensive resources, guides, and FAQs for self-learning.
24/7 Technical Support – Available for enterprise customers via email, phone, and a support portal.
Dedicated Customer Success Managers – Assist with onboarding, optimization, and troubleshooting.
Community Support (Zeek & Suricata Forums) – Open-source community discussions for troubleshooting and knowledge sharing.
Open NDR by Corelight implements multiple security measures to protect data, ensuring robust threat detection, compliance, and secure network monitoring. These measures include:
End-to-End Encryption – Secures network data during transmission and storage.
TLS/SSL Decryption Support – Enables analysis of encrypted traffic while maintaining security.
Role-Based Access Control (RBAC) – Restricts access based on user roles to prevent unauthorized data exposure.
Log Integrity & Tamper Detection – Ensures security logs remain unaltered for forensic investigations.
AI-Powered Behavioral Analytics – Detects anomalies and malicious activities using machine learning.
Deep Packet Inspection (DPI) – Analyzes network traffic for hidden threats.
Zero-Day Attack Detection – Identifies new and evolving threats using real-time heuristics.
Lateral Movement & Data Exfiltration Detection – Prevents attackers from spreading within the network.
Compliance with Security Standards – Aligns with GDPR, NIST, ISO 27001, and SOC 2 requirements.
Audit Logging & Forensic Capabilities – Provides detailed records of network activities for compliance audits.
Automated Incident Response – Speeds up threat mitigation with automated playbooks and integrations.
Secure API Access – Ensures encrypted communication between Open NDR and third-party tools.
Cloud-Native Security – Supports secure deployments in AWS, Azure, and GCP with cloud-specific protections.
Corelight Open NDR platform offers robust policies regarding data ownership and portability, emphasizing user control and flexibility.
Data Ownership:
Users maintain full ownership of the data processed and generated by the Open NDR platform. This approach ensures that organizations have complete authority over their network data, allowing them to manage, analyze, and store it according to their internal policies and compliance requirements.
Data Portability:
The platform is designed with an open data framework, facilitating seamless integration with various security tools and systems. Key aspects of its data portability include:
Open Data Formats: Utilizing standardized, non-proprietary data formats enables easy export and import of data across different platforms without compatibility issues.
Integration Capabilities: The platform supports integration with popular Security Information and Event Management (SIEM) systems, Extended Detection and Response (XDR) solutions, and data lakes, enhancing interoperability within an organization's security infrastructure.
Corelight Open NDR Platform aligns with several key compliance standards,
FIPS 140-2: Corelight Sensors comply with the Federal Information Processing Standard 140-2, which specifies security requirements for cryptographic modules protecting sensitive information.
NIAP Common Criteria: Corelight has achieved certification under the National Information Assurance Partnership (NIAP) Common Criteria, ensuring the platform meets rigorous security evaluation standards. Additional information is available upon request.
Authority to Operate (ATO): The platform has been authorized for operational use by agencies within the Department of Defense (DoD), Intelligence Community (IC), Federal Civilian sector, and companies in the Defense Industrial Base (DIB), demonstrating its adherence to stringent security and operational standards.
SOC 2: Corelight adheres to the Service Organization Control 2 (SOC 2) standards, which focus on managing customer data based on principles of security, availability, processing integrity, confidentiality, and privacy.
TAA Compliance: The platform complies with the Trade Agreements Act (TAA), ensuring that products are manufactured or undergo substantial transformation in designated countries.

Open NDR
By Corelight, Inc