The most valuable feature is the embedded IDS from Suricata.
Corelight Open NDR offers ease of use with visibility into a client's environment and simplifies cyber attack remediation using correlated metrics. It's praised for its easy deployment and customizable dashboards, with its Suricata-embedded IDS being a standout feature. However, users find the architecture complex, and the lack of recent feature updates, high costs, and the absence of a graphical user interface have been noted drawbacks. Machine learning potential and price reductions are areas of improvement.





