# Arkime vs Corelight

| Attribute | Arkime | Corelight |
|---|---|---|
| **Vioscale score** | 46.9 (32% (low)) | 12 (15% (low)) |
| activity.commits_last_30d | 46 | - |
| adoption.dependent_repos | 0 | - |
| adoption.github_stars | 7,459 | - |
| deployment.options | `{"self_hosted":true}` | `{"cloud":true,"hybrid":true,"on_prem":true,"air_gapped":true,"self_hosted":true}` |
| description.long | A network monitoring tool that passively captures and analyzes traffic, extracting detailed session information and providing searchable records with flexible retention policies for integration into existing security infrastructure. | Platform that monitors network traffic to identify security threats and accelerate incident response. Uses machine learning, behavioral analytics, and protocol-level analysis built on the open-source Zeek framework to deliver actionable intelligence for security operations centers. |
| integrations.count | 6 | 18 |
| integrations.list | `[{"name":"PassiveTotal"},{"name":"VirusTotal"},{"name":"Censys"},{"name":"Shodan"},{"name":"Slack"},{"name":"Elasticsearch"}]` | `[{"name":"Splunk"},{"name":"Splunk Enterprise Security"},{"name":"Splunk SOAR"},{"name":"Microsoft Defender"},{"name":"Microsoft Sentinel"},{"name":"Microsoft Entra ID"},{"name":"CrowdStrike"},{"name":"Google Cloud Security"},{"name":"Elastic"},{"name":"Kafka"},{"name":"Syslog"},{"name":"AWS"},{"name":"Azure"},{"name":"Google Cloud"},{"name":"VMware"},{"name":"Hyper-V"},{"name":"S3"},{"name":"Zeek"}]` |
| language.primary | C | - |
| license.spdx | Apache-2.0 | - |
| market.availability | - | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| pricing | `{"type":"open_source","freeTier":true,"sourceUrl":"https://arkime.com","retrievedAt":"2026-08-19T14:43:16.285Z"}` | `{"type":"quote","freeTier":false,"sourceUrl":"https://corelight.com","retrievedAt":"2026-08-19T14:44:31.898Z"}` |
| pricing.free_tier | yes | no |
| pricing.model | commercial | quote |
| pricing.price_level | free | unknown |
| pricing.transparent | - | no |
| release.cadence_days | 24 | - |
| release.history | `[{"url":"https://github.com/arkime/arkime/releases/tag/last-commit7","date":"2026-05-07T14:38:54Z","type":"prerelease","version":"last-commit7"},{"url":"https://github.com/arkime/arkime/releases/tag/last-commit6","date":"2024-10-24T15:25:05Z","type":"prerelease","version":"last-commit6"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.7.0","date":"2026-08-19T14:36:16Z","type":"stable","version":"v6.7.0"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.6.0","date":"2026-07-09T15:11:19Z","type":"stable","version":"v6.6.0"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.5.0","date":"2026-06-15T14:45:16Z","type":"stable","version":"v6.5.0"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.4.0","date":"2026-05-20T15:03:57Z","type":"stable","version":"v6.4.0"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.3.1","date":"2026-05-04T22:57:03Z","type":"stable","version":"v6.3.1"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.3.0","date":"2026-05-04T16:12:15Z","type":"prerelease","version":"v6.3.0"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.2.0","date":"2026-04-20T14:45:21Z","type":"stable","version":"v6.2.0"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.1.1","date":"2026-04-06T12:40:00Z","type":"stable","version":"v6.1.1"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.1.0","date":"2026-03-18T13:27:48Z","type":"stable","version":"v6.1.0"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.0.1","date":"2026-03-09T15:37:08Z","type":"stable","version":"v6.0.1"},{"url":"https://github.com/arkime/arkime/releases/tag/v6.0.0","date":"2026-03-02T14:15:40Z","type":"stable","version":"v6.0.0"},{"url":"https://github.com/arkime/arkime/releases/tag/v5.8.3","date":"2025-12-02T15:24:14Z","type":"stable","version":"v5.8.3"},{"url":"https://github.com/arkime/arkime/releases/tag/last-commit","date":"2023-12-11T12:49:37Z","type":"prerelease","version":"last-commit"},{"url":"https://github.com/arkime/arkime/releases/tag/v5.8.2","date":"2025-10-27T20:30:16Z","type":"stable","version":"v5.8.2"},{"url":"https://github.com/arkime/arkime/releases/tag/v5.8.1","date":"2025-10-20T17:59:43Z","type":"stable","version":"v5.8.1"},{"url":"https://github.com/arkime/arkime/releases/tag/v5.8.0","date":"2025-09-22T14:29:54Z","type":"stable","version":"v5.8.0"},{"url":"https://github.com/arkime/arkime/releases/tag/v5.7.1","date":"2025-07-23T20:01:19Z","type":"stable","version":"v5.7.1"},{"url":"https://github.com/arkime/arkime/releases/tag/v5.7.0","date":"2025-06-11T14:47:02Z","type":"stable","version":"v5.7.0"}]` | - |
| security.disclosure_policy | - | yes |
| security.scorecard | 6.7 | - |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Farkime%2Farkime&per_page=100","last_12m":0,"max_severity":null}` | - |

## Capabilities (Network Security)

| Capability | Arkime | Corelight |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Deployment model | - | - |
| Behavioral anomaly detection | - | - |
| Full packet pcap retention | - | - |
| Encrypted traffic metadata analysis | - | - |
| Active endpoint containment response | - | - |
| Host microsegmentation | - | - |
| Network access control 802 1x | - | - |
| EDR crowdstrike sentinelone integration | - | - |
| Iot ot device discovery | - | - |
| Fips 140 2 certification | - | - |
| SOC2 type ii | - | - |
| ISO 27001 | - | - |
| Pricing model | - | - |

*Source: Vioscale. Generated 2026-09-01T14:40:02.666Z. "-" = undocumented, not absent.*
