SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Corelight launches AI tools for faster, auditable SOCs

Corelight launches AI tools for faster, auditable SOCs

Mon, 28th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Corelight has launched two new artificial intelligence tools for security operations centres and expanded its detection coverage for AI-related threats. The release is intended to reduce barriers to AI use in security teams.

The new products are Agent Builder Library and Natural Language Query. Agent Builder Library packages Corelight's network forensics playbooks, field explanations and investigation decision trees into deterministic logic that can run inside customer AI agents, SOAR workflows and private large language model environments, including air-gapped networks.

Natural Language Query targets another hurdle in security operations: query syntax. The tool lets analysts ask questions in plain English and receive LogScale queries that can be edited, validated and run against their own data.

Every verdict produced by the AI tools is linked to the underlying playbook, behavioural signals and evidence chain used to reach the conclusion. That audit trail can support reporting and incident response requirements tied to NIS2, DORA, SEC disclosure rules and CMMC 2.0.

The launch comes as cyber security vendors and corporate defenders face pressure to respond more quickly to attacks shaped by AI. Corelight said the median time to exploit a vulnerability has dropped to about five days, while enterprise patching cycles often still run from 60 to 150 days.

Vijit Nair, Senior Vice President of Product at Corelight, said the company is trying to close the gap between the speed of attackers' AI use and the ability of security teams to respond with tools analysts can inspect and trust.

"The instinct is to fight AI-speed attacks with AI-speed defense, and that's right. But speed without expertise is just fast guessing," said Vijit Nair, Senior Vice President of Product at Corelight. "We've packaged a decade of network forensics knowledge into building blocks that any AI agent can execute, whether it's ours or the customer's own. The result is an AI investigation that's transparent enough for a skeptical analyst to verify line-by-line, accessible enough for a day-one hire to use immediately, and operational enough to put these agentically validated, pre-triaged threats directly in front of the human as quickly as possible."

Broader detection

Alongside the new investigation tools, Corelight has expanded its threat detection to cover AI supply-chain compromise, suspicious AI gateway and provider activity, attacks on exposed AI infrastructure and unusual AI application behaviour. It is also adding behavioural analytics for stealth command-and-control traffic and data exfiltration.

Those detections use 31-day subnet-level destination history and per-host upload baselining to identify outbound connections to previously unseen countries and unusual data transfers. Signals from the expanded anomaly engine feed into the same investigation playbooks used by the new AI tools.

The approach reflects a wider shift in the security market, where automation alone is no longer enough for many buyers. Regulated organisations and operators of isolated networks increasingly want systems that can explain why an alert was raised and allow investigation logic to run outside a vendor's cloud.

Andrew Braunberg, Principal Analyst at Omdia, said those requirements are becoming central to how security tools are assessed.

"Security teams are increasingly investigating the use of AI to combat the accelerating speed of threat actors who have been early adopters of the technology," said Andrew Braunberg, Principal Analyst at Omdia. "The ability to automate security workflows are quickly becoming expected capabilities in SecOps solutions but the tools that become widely adopted in the SOC will need to do more than just automate, they will need to document, evaluate, and explain. Inspectable logic that can run outside the vendor's cloud isn't a nice-to-have anymore; for a lot of buyers, especially in regulated and air-gapped environments, it's a primary evaluation criterion."

Market pressure

San Francisco-based Corelight has built its business around network evidence and analytics used by large companies, government agencies and universities. It was founded by the creators of Zeek, the open-source network security technology.

Its latest move builds on earlier work in agentic triage, where AI is used to automate repetitive work for security analysts. Corelight is now extending that model into tools intended to reduce reliance on specialist network expertise and familiarity with proprietary query languages.

The timing reflects broader concern among defenders that AI is not only speeding up malware development and reconnaissance, but also shortening the period between disclosure of a flaw and active exploitation. That has increased pressure on security operations centres to investigate and triage threats faster without giving up traceability.

Corelight's focus is on making AI-generated investigation results reviewable by human analysts rather than relying on opaque scoring systems. Every signal generated by the expanded anomaly engine feeds into the same expert-authored investigation logic, producing an auditable, evidence-backed verdict.