Security Onion 2.4.180 now available including new features, updated components, and quality of life improvements!
blog.securityonion.net/2025/09/secu...
@securityonion.bsky.social
By defenders. For defenders. Peel back the layers of your network and make your adversaries cry. https://www.securityonion.com
Security Onion 2.4.180 now available including new features, updated components, and quality of life improvements!
blog.securityonion.net/2025/09/secu...
π¨ Security Onion 2.4.170 now available including JA4, more SOC dashboards, and updated components! π¨
πLet's find more hackers! π
If you like Security Onion, please like and share to help spread the word!
blog.securityonion.net/2025/08/secu...
For more information, please see the blog post!
blog.securityonion.net/2025/06/secu...
This leverages Playbooks to show you plays associated with the alert. These plays include questions which help guide your investigation. Each question has an associated query and the results of that query will be automatically displayed to help you answer the question.
25.06.2025 18:35 β π 0 π 0 π¬ 1 π 0Security Onion 2.4.160 now available including Playbooks, Guided Analysis, MCP Server, and more!
Have you ever had an alert and were unsure of what to do next? In this release, when you expand an alert you'll see a new tab called Guided Analysis.
We've got a new AI-powered Playbooks feature coming in Security Onion 2.4.160 that will turbocharge your analysis and incident response!
www.youtube.com/watch?v=SLGR...
Check out our latest video, covering the Notifications feature in Security Onion Pro. Send your alerts directly to another platform, like email, Slack, or Jira!
www.youtube.com/watch?v=quy8...
Today, we are releasing Security Onion 2.4.150 which includes a new Pro feature called MoM (Manager of Managers).
If you have multiple Security Onion deployments, check out this new feature that will allow you to manage them from a single manager!
blog.securityonion.net/2025/05/secu...
Tattoo of an onion with an arrow through it and a banner beneath that says MOM
π§
β₯οΈSecurity Onion 2.4.150: Celebrating Mother's Day with MoM (Manager of Managers) π§
β₯οΈ
Yesterday was Mother's Day and we are very thankful for our mothers!
Thanks to Simply Cyber for having me on the podcast to talk about @securityonion.bsky.social !
Peeling Back the Network Layers with Doug Burks | S3 E2
www.youtube.com/watch?v=FNB6...
There's also lots of good information in the Elasticsearch section of our documentation:
docs.securityonion.net/en/2.4/elast...
Need more information on index lifecycle management? Good news, there's a primer on our Youtube channel!
www.youtube.com/watch?v=Y6HV...
Upcoming change to Elasticsearch index management in Security Onion -- read this, especially if you're running a distributed, multinode deployment.
blog.securityonion.net/2025/04/upco...
Index Lifecycle Management in Security Onion
www.youtube.com/watch?v=Y6HV...
Security Onion is BY defenders FOR defenders!
If you like Security Onion, please scroll to the very top of this thread and LIKE and REPOST the first post of the thread to help spread the word!
THANKS!
There are many more fixes included in this release!
For more information, please see the full blog post at:
blog.securityonion.net/2025/03/secu...
This release also adds a new feature to SOC Config that allows you to move certain configuration entries up or down. This includes things like SOC Dashboard queries, SOC Hunt queries, and SOC Actions:
25.03.2025 13:59 β π 0 π 0 π¬ 2 π 0Zeek 7.0.6 includes some bug fixes:
github.com/zeek/zeek/re...
The main focus of this release is upgrading Suricata and Zeek.
Suricata 7.0.9 includes some security fixes:
suricata.io/2025/03/18/s...
Security Onion 2.4.140 now available including Suricata 7.0.9, Zeek 7.0.6, and much more!
For more details, please see the thread π§΅and the link below!
We've just announced a Detection Engineering and Analysis course, coming up this July in Columbia, MD. Register now for an early bird discount!
blog.securityonion.net/2025/03/earl...
Quick Malware Analysis: REMCOS RAT pcap from 2025-03-10
blog.securityonion.net/2025/03/quic...
If you like Security Onion, please scroll to the top of this thread and LIKE and SHARE with your network to help spread the word!
Thanks!
For more information and a full screenshot tour, please see our blog post at:
blog.securityonion.net/2025/03/secu...
This release includes support for some additional Zeek logs for protocol metadata like NTP and LDAP.
11.03.2025 17:48 β π 0 π 0 π¬ 1 π 0Our SOC Configuration interface is now even easier to use, especially for config items like Actions, Dashboard queries, and Hunt queries.
11.03.2025 17:48 β π 0 π 0 π¬ 1 π 0SOC Alerts has an advanced interface that provides more data similar to SOC Dashboards. You can now permanently enable that advanced interface using the toggle under the Options menu.
11.03.2025 17:48 β π 0 π 0 π¬ 1 π 0Also, we've included ALL Elastic integrations in this release!
11.03.2025 17:48 β π 0 π 0 π¬ 1 π 0The main focus of this release is upgrading to Elastic 8.17.3!
11.03.2025 17:47 β π 0 π 0 π¬ 1 π 0Security Onion 2.4.130 now available including Elastic 8.17.3 and much more!
Please see thread π§΅below for more details!