San Francisco – September 18, 2026 -- Corelight has launched the Agent Builder Library and Natural Language Query, two tools designed to let security operations centers match the speed of AI-driven cyberattacks without losing auditability over investigation logic.
Attackers now exploit vulnerabilities in roughly five days, far outpacing patch cycles
Enterprise patching cycles typically run 60 to 150 days, but the median time to exploit has dropped to approximately five days, according to Corelight. The company warns that with emerging Mythos-class AI models, attackers may exploit vulnerabilities before defenders even know a flaw exists, making faster patching an inadequate defense on its own.
Corelight packages a decade of forensics expertise into exportable, deterministic playbooks
The Agent Builder Library provides triage playbooks, field explanations, entity-pivoting guides, and investigation decision trees built from over a decade of Corelight's network forensics work. Because the logic is deterministic rather than probabilistic, security teams can export it into their own AI agents, SOAR workflows, or private LLM environments, including air-gapped and classified networks with no cloud connectivity.
Natural Language Query lets analysts skip specialized syntax to interrogate network evidence
Natural Language Query allows analysts to ask plain-English questions and receive validated, executable LogScale queries. Orchestrated AI sub-agents build a query plan and return results with visible chain-of-thought reasoning, and the generated query remains editable for analysts to refine or learn from.
"Speed without expertise is just fast guessing,