Skip to content
@corelight

Corelight, Inc.

Corelight is the most powerful network visibility solution for information security professionals, founded by the creators of open-source Zeek.

Popular repositories Loading

  1. zeek-cheatsheets zeek-cheatsheets Public

    Zeek Log Cheatsheets

    292 46

  2. community-id-spec community-id-spec Public

    An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

    Python 179 26

  3. threat-hunting-guide threat-hunting-guide Public

    51 12

  4. raspi-corelight raspi-corelight Public

    Corelight@Home script

    Shell 42 5

  5. zeek-community-id zeek-community-id Public

    Zeek support for Community ID flow hashing.

    Zeek 35 18

  6. zeek2es zeek2es Public

    A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!

    Python 35 5

Repositories

Showing 10 of 148 repositories
  • zeek-quasarrat-detector Public

    Zeek detector for QuasarRat

    corelight/zeek-quasarrat-detector’s past year of commit activity
    Shell 2 BSD-3-Clause 0 0 0 Updated Jun 20, 2025
  • zeek-asyncrat-detector Public

    A Zeek based AsyncRAT malware detector.

    corelight/zeek-asyncrat-detector’s past year of commit activity
    Shell 2 BSD-3-Clause 0 0 0 Updated Jun 20, 2025
  • ecs-templates Public

    Corelight or Zeek Elastic Common Schema Templates

    corelight/ecs-templates’s past year of commit activity
    Python 9 BSD-3-Clause 6 2 0 Updated Jun 20, 2025
  • ecs-logstash-mappings Public

    Mapping Corelight or Zeek data to Elastic Common Schema logs

    corelight/ecs-logstash-mappings’s past year of commit activity
    12 BSD-3-Clause 6 1 0 Updated Jun 20, 2025
  • ecs-mapping Public

    Mapping Corelight or Zeek data to Elastic Common Schema fields

    corelight/ecs-mapping’s past year of commit activity
    34 BSD-3-Clause 15 1 0 Updated Jun 20, 2025
  • corelight-cloud Public

    IaC used to deploy Corelight Sensors into various Cloud Providers.

    corelight/corelight-cloud’s past year of commit activity
    HCL 2 MIT 1 0 0 Updated Jun 18, 2025
  • terraform-gcp-enrichment Public

    Terraform for Corelight's GCP Cloud Enrichment.

    corelight/terraform-gcp-enrichment’s past year of commit activity
    HCL 0 MIT 2 2 0 Updated Jun 16, 2025
  • terraform-gcp-sensor Public

    Terraform for Corelight's GCP Cloud Sensor Deployment.

    corelight/terraform-gcp-sensor’s past year of commit activity
    HCL 1 MIT 0 0 0 Updated Jun 16, 2025
  • corelight/Zeek-CVE-Enrichment’s past year of commit activity
    Zeek 1 2 0 1 Updated Jun 13, 2025
  • corelight/Zeek-Endpoint-Enrichment’s past year of commit activity
    Zeek 2 1 0 1 Updated Jun 13, 2025