This leverages Playbooks to show you plays associated with the alert. These plays include questions which help guide your investigation. Each question has an associated query and the results of that query will be automatically displayed to help you answer the question.
25.06.2025 18:35 β π 0 π 0 π¬ 1 π 0
Security Onion 2.4.160 now available including Playbooks, Guided Analysis, MCP Server, and more!
Have you ever had an alert and were unsure of what to do next? In this release, when you expand an alert you'll see a new tab called Guided Analysis.
25.06.2025 18:34 β π 2 π 2 π¬ 1 π 0
YouTube video by Security Onion
Sneak Peek: Security Onion Playbooks
We've got a new AI-powered Playbooks feature coming in Security Onion 2.4.160 that will turbocharge your analysis and incident response!
www.youtube.com/watch?v=SLGR...
18.06.2025 13:28 β π 1 π 1 π¬ 0 π 1
YouTube video by Security Onion
Security Onion Pro Notifications
Check out our latest video, covering the Notifications feature in Security Onion Pro. Send your alerts directly to another platform, like email, Slack, or Jira!
www.youtube.com/watch?v=quy8...
12.06.2025 17:12 β π 1 π 0 π¬ 0 π 1
Security Onion 2.4.150: Celebrating Mother's Day with MoM (Manager of Managers)
Yesterday was Mother's Day and we are very thankful for our mothers! Today, we are releasing Security Onion 2.4.150 which includes a new Pro...
Today, we are releasing Security Onion 2.4.150 which includes a new Pro feature called MoM (Manager of Managers).
If you have multiple Security Onion deployments, check out this new feature that will allow you to manage them from a single manager!
blog.securityonion.net/2025/05/secu...
12.05.2025 17:14 β π 0 π 0 π¬ 0 π 0
Tattoo of an onion with an arrow through it and a banner beneath that says MOM
π§
β₯οΈSecurity Onion 2.4.150: Celebrating Mother's Day with MoM (Manager of Managers) π§
β₯οΈ
Yesterday was Mother's Day and we are very thankful for our mothers!
12.05.2025 17:13 β π 1 π 1 π¬ 1 π 1
YouTube video by Simply Cyber - Gerald Auger, PhD
Peeling Back the Network Layers with Doug Burks | S3 E2
Thanks to Simply Cyber for having me on the podcast to talk about @securityonion.bsky.social !
Peeling Back the Network Layers with Doug Burks | S3 E2
www.youtube.com/watch?v=FNB6...
25.04.2025 14:56 β π 1 π 2 π¬ 0 π 0
Elasticsearch β Security Onion Documentation 2.4 documentation
There's also lots of good information in the Elasticsearch section of our documentation:
docs.securityonion.net/en/2.4/elast...
23.04.2025 12:29 β π 0 π 0 π¬ 0 π 0
YouTube video by Security Onion
Index Lifecycle Management in Security Onion
Need more information on index lifecycle management? Good news, there's a primer on our Youtube channel!
www.youtube.com/watch?v=Y6HV...
23.04.2025 12:29 β π 0 π 0 π¬ 1 π 0
YouTube video by Security Onion
Index Lifecycle Management in Security Onion
Index Lifecycle Management in Security Onion
www.youtube.com/watch?v=Y6HV...
17.04.2025 14:08 β π 2 π 1 π¬ 0 π 1
Security Onion is BY defenders FOR defenders!
If you like Security Onion, please scroll to the very top of this thread and LIKE and REPOST the first post of the thread to help spread the word!
THANKS!
25.03.2025 13:59 β π 0 π 0 π¬ 0 π 0
This release also adds a new feature to SOC Config that allows you to move certain configuration entries up or down. This includes things like SOC Dashboard queries, SOC Hunt queries, and SOC Actions:
25.03.2025 13:59 β π 0 π 0 π¬ 2 π 0
Zeek 7.0.6 includes some bug fixes:
github.com/zeek/zeek/re...
25.03.2025 13:58 β π 0 π 0 π¬ 1 π 0
The main focus of this release is upgrading Suricata and Zeek.
Suricata 7.0.9 includes some security fixes:
suricata.io/2025/03/18/s...
25.03.2025 13:58 β π 0 π 0 π¬ 1 π 0
If you like Security Onion, please scroll to the top of this thread and LIKE and SHARE with your network to help spread the word!
Thanks!
11.03.2025 17:49 β π 0 π 0 π¬ 0 π 0
This release includes support for some additional Zeek logs for protocol metadata like NTP and LDAP.
11.03.2025 17:48 β π 0 π 0 π¬ 1 π 0
Our SOC Configuration interface is now even easier to use, especially for config items like Actions, Dashboard queries, and Hunt queries.
11.03.2025 17:48 β π 0 π 0 π¬ 1 π 0
SOC Alerts has an advanced interface that provides more data similar to SOC Dashboards. You can now permanently enable that advanced interface using the toggle under the Options menu.
11.03.2025 17:48 β π 0 π 0 π¬ 1 π 0
Also, we've included ALL Elastic integrations in this release!
11.03.2025 17:48 β π 0 π 0 π¬ 1 π 0
The main focus of this release is upgrading to Elastic 8.17.3!
11.03.2025 17:47 β π 0 π 0 π¬ 1 π 0