Corelight Extends Gen AI Leadership in NDR with New MCP Server and Prompt Playbooks for Faster Alert Triage and Resolution

Trending...
~ Corelight, a leading provider of network detection and response (NDR) solutions, has announced the launch of its GenAI Accelerator Pack. This new offering includes a Model Context Protocol (MCP) Server, Analyst Assistant Promptbooks, and Investigation Promptbooks, all designed to enhance and accelerate security operations center (SOC) workflows.

The GenAI Accelerator Pack leverages industry-standard network evidence and the power of large language models (LLMs) to provide SOC teams with superhuman triage capabilities. This pack will be showcased at the Black Hat Network Operations Center (NOC) during the conference in Las Vegas from August 2-7. Corelight is the sole provider of NDR capabilities at this event, constantly monitoring the purpose-built network for any malicious activity.

This latest announcement further solidifies Corelight's position as a leader in the NDR segment. The company has been at the forefront of integrating GenAI workflow automation functionality and co-developing partnerships with LLMs. Additionally, Corelight's GenAI-powered Guided Triage capability has set a new standard for enabling the agentic SOC ecosystem.

More on nvtip.com
According to Greg Bell, Chief Strategy Officer at Corelight, this launch is a natural extension of their efforts to leverage AI for robust analytics and workflow acceleration. He states that this is the third pillar of their AI strategy, which focuses on supporting the emerging agentic SOC ecosystem. By combining rich network evidence, expert-authored detections, and LLM-driven reasoning, Corelight aims to provide SOC teams with unparalleled triage capabilities without sacrificing trust or transparency.

The Corelight GenAI Accelerator Pack offers several features that make it stand out in the market. The MCP Server provides analysts with a programmatic interface to access Corelight log, alert, and detection data through pre-built tools using natural language queries. The Investigation Promptbooks offer automated investigation workflows for common alert types with complete transparency on each step taken. The Analyst Assistant Promptbooks provide a wide range of LLM prompts and sample data to support day-to-day analyst activities.

More on nvtip.com
These Promptbooks are an extension of Corelight's existing workflow automation capabilities from their Investigator SaaS product, now available to sensor-only customers as well. This allows for succinct and actionable insights that can be easily integrated into other AI workstreams or directly used by security practitioners. It also enables the automation and acceleration of analysis for various alert types, including network security alerts generated by Corelight and other types such as EDR and ITDR.

Bell believes that the future of cybersecurity lies in evidence-first and AI-accelerated solutions, making Corelight uniquely positioned to deliver modern solutions for the agentic SOC. The GenAI Accelerator Pack is currently available in private preview to existing Corelight customers, who can engage their account teams to turn on access as needed.

To learn more about this latest release in Corelight's AI journey, visit their website at https://corelight.com/blog/llm-prompts-for-netw.... With the launch of the GenAI Accelerator Pack, Corelight continues to drive innovation in the NDR segment and empower SOC teams with advanced capabilities to combat cyber threats.
Filed Under: Business

Show All News | Report Violation

0 Comments

Latest on nvtip.com