Loading organizations...

§ Private Profile · San Francisco, CA, USA
Provides network traffic analysis solutions for cybersecurity, built on Zeek, for enterprise security operations and government agencies.
Based in San Francisco, California, Corelight develops network traffic analysis and cybersecurity solutions built on the open-source Zeek security framework. The company provides enterprise sensors and software that transform network and cloud activity into actionable evidence for threat hunting, incident response, network visibility, and machine learning analytics. Operating with a workforce of 101 to 200 employees, the enterprise has raised $159.2 million in total venture funding and achieved an estimated valuation between $600 million and $900 million. Its network security products are utilized by major government agencies, large universities, and Fortune 500 corporations, including technology companies like Amazon. The firm's financial backing comes from prominent venture capital and corporate investors such as Accel Partners, Cisco Investments, and Energy Impact Partners. Corelight was founded in 2016 by Vern Paxson, Robin Sommer, Seth Hall, and Gregory Bell.
Corelight has raised $309.0M across 5 funding rounds.
Corelight has raised $309.0M in total across 5 funding rounds.
Corelight is a cybersecurity company specializing in an open Network Detection and Response (NDR) platform that transforms network and cloud traffic into actionable evidence for threat detection, investigation, and hunting.[1][2][3] It serves Fortune 500 enterprises, government agencies, research institutions, and state/local/education (SLED) organizations by solving visibility gaps in complex networks, enabling faster incident response, reduced false positives, and compliance with standards like NIST and CJIS through AI-driven detections powered by Zeek, Suricata, and YARA.[1][2][4] The platform integrates with tools like Splunk, CrowdStrike, and Microsoft Sentinel, delivering multi-layered security including intrusion detection, packet capture, and behavioral analytics, with strong growth including 40% YoY ARR and 300% YoY in AI/SaaS NDR solutions as of 2024.[3][7]
Corelight was founded in 2013 in San Francisco by the creators of the Bro/Zeek open-source network security project, bringing deep expertise in network analysis to commercial scale.[1][2][7] The idea emerged from the need to deploy Zeek and Suricata at enterprise scale for wire- and application-layer traffic analysis, addressing limitations in open-source tools for real-time threat remediation in complex environments.[2] Early traction came from trust by large enterprises, governments, and universities, evolving into the industry's fastest-growing scaled NDR platform with backing from investors like H.I.G. Capital.[2][7]
Corelight stands out in NDR through these key strengths:
Corelight rides the AI-driven cybersecurity wave, particularly the shift to agentic SOCs and evidence-based defense amid rising sophisticated threats that evade endpoint tools.[3][5][6] Timing is ideal with cloud migrations, hybrid environments, and regulations like NIST demanding network visibility, where Corelight's open NDR fills gaps in XDR ecosystems by providing "ground truth" from network traffic.[1][4][7] Market forces like increasing attacks on SLED and enterprises favor its proactive model, influencing the ecosystem through partnerships (CrowdStrike, Microsoft) and open-source roots, enabling defenders to up-level from reactive T1 tasks to expert T2/T3 analysis.[2][6]
Corelight is positioned for continued dominance in NDR, with AI/SaaS growth signaling expansion into pre-emptive detection and ecosystem integrations amid escalating threats.[7] Trends like AI SOCs, multi-cloud security, and Zero Trust will propel it, potentially evolving influence through deeper consortia ties and scaled deployments. As network evidence becomes indispensable against stealthy attacks, Corelight's open platform will empower data-first defenders, solidifying its role from visibility provider to AI-orchestrated resilience leader—echoing its origins in transforming open-source power for enterprise cybersecurity.
Corelight has raised $309.0M in total across 5 funding rounds.
Corelight's investors include Accel, Acrobator Ventures, Amino Capital, Blu Venture Investors, Canaan Partners, CapitalG, Cisco Investments, KRM Interests LLC, Liquid 2 Ventures, Rainfall Ventures, Two Bear Capital, WestWave Capital.
Corelight has raised $309.0M across 5 funding rounds. Most recently, it raised $150.0M Series E in April 2024.
| Date | Round | Lead Investors | Other Investors | Status |
|---|---|---|---|---|
| Apr 1, 2024 | $150M Series E | Accel | Acrobator Ventures, Amino Capital, BLU Venture Investors, Canaan Partners, CapitalG, Cisco Investments, KRM Interests LLC, Liquid 2 Ventures, Rainfall Ventures, TWO Bear Capital, WestWave Capital, Y Combinator, SUE XU, GUR Talpaz | Announced |
| Sep 2, 2021 | $75M Series D | Shawn Cherian | JAY Emmanuel, CrowdStrike Ventures, Lorenzo Thione | Announced |
| Oct 1, 2019 | $50M Series C | Accel, Insight Partners | Dell Technologies Capital, Erel Margalit, Kleiner Perkins, Lightspeed Venture Partners, Sapphire Ventures, Social Capital | Announced |
| Sep 11, 2018 | $25M Series B | Steve Herrod | — | Announced |
| Jul 1, 2017 | $9M Series A | Accel | Dell Technologies Capital, Kleiner Perkins, Lightspeed Venture Partners, Sapphire Ventures, Social Capital, Steven Mccanne, Osage University Partners | Announced |