Corelight
Corelight Entity Collection for Enhanced Security Visibility
Pages
6
Time to read
8 mins
Publication
Language
English
Pages
6
Time to read
8 mins
Publication
Language
English
This white paper discusses the Corelight Entity Collection, which aims to improve visibility into devices, applications, and users within enterprise networks. It addresses the challenges faced by analysts in understanding alerts and incidents due to the difficulty in accessing necessary information. The Corelight Entity Collection enhances incident response and threat hunting workflows by providing powerful identification capabilities that map and defend the network environment. It includes the Known Entities Package, Application Identification Package, and Local Subnets Package, each designed to summarize and synthesize relevant data from Corelight logs. The Known Entities Package offers summaries of network elements, while the Application Identification Package categorizes over 150 applications. Additionally, the Local Subnets Package identifies local network settings to aid in investigations. The paper outlines various use cases, including context retrieval, asset inventory management, and Zero Trust policy violation detection, emphasizing the efficiency gained through summarized data.