Corelight
Global Law Firm Enhances Threat Hunting Capabilities
Pages
3
Time to read
5 mins
Publication
Language
English
Pages
3
Time to read
5 mins
Publication
Language
English
This case study outlines how a major international law firm improved its threat hunting capabilities through the implementation of Corelight's AP 1000 Sensor and the open-source Zeek Network Security Monitor. The firm faced challenges in gaining the necessary visibility to effectively hunt for threats across its network, which spanned multiple data centers and satellite offices with high throughput speeds. The information security engineer discovered Corelight while researching commercial solutions and noted the limitations of their initial attempts to deploy an open-source Zeek server. After evaluating various products, they found that Corelight's solution met their scalability and ease-of-use requirements. The integration of Corelight's sensor with the Real Intelligence Threat Analysis (RITA) tool enabled the security team to analyze Zeek logs for threat hunting, allowing for a proactive defense against advanced attacks. The firm reported increased efficiency in threat hunting and reduced maintenance burdens, enabling the team to focus on identifying potential threats more effectively.