Seth G. · @secboxtc
13 followers · 306 posts · Server social.vivaldi.net

For users of @kalilinux and @securityonion products:

I have freed up an old computer to use as a server on my home network again. For an IPS, should I go with or , and why?

#kali #kalipurple #securityonion

Last updated 2 years ago

2.3.220 now available including:

βœ… 8.6.2
βœ… 9.2.10
βœ… 4.27.1
βœ… 5.0.7

and more!

blog.securityonion.net/2023/02

Looking for a fun project? πŸ˜€

Want to practice your πŸ” and skills?

Install πŸ§…2.3.220 in a VM:
docs.securityonion.net/en/2.3/

Then follow along with our recent quick analysis blog posts:
blog.securityonion.net/search/

You can then stand up a production deployment and sniff live traffic from a tap or span port. You'll get NIDS alerts, protocol metadata, and full packet capture!
docs.securityonion.net/en/2.3/

Then augment that network visibility with host visibility by deploying endpoint agents:
docs.securityonion.net/en/2.3/

Once you find something of interest in your network or endpoint logs, you can escalate to a case:
docs.securityonion.net/en/2.3/

Inside the case, you can identify indicators and analyze them using Analyzers:
docs.securityonion.net/en/2.3/

Looking for more documentation?

It's built into our web interface for 2.3.220 but you can also find it online at:
securityonion.net/docs

You can also purchase a printed copy of the documentation at securityonion.net/book with proceeds going to Rural Technology Fund!

The printed book also includes an inspiring foreword by @taosecurity and a 20% discount code for our certification and on-demand training!

#securityonion #elastic #grafana #fleetdm #zeek #cybersecurity #threathunting #incidentresponse #malware

Last updated 3 years ago

Josh Lemon · @joshlemon
130 followers · 31 posts · Server infosec.exchange

If you're keen to learn more about or 's, blogs like this which walk you through using , with a malicious sample from the wild, are great to practice your skills.

blog.securityonion.net/2023/02

#networkforensics #nsm #securityonion #dfir

Last updated 3 years ago

Looking for a fun project? πŸ˜€β€‹

Want to practice your πŸ”β€‹ and skills?

Install πŸ§…β€‹ in a VM:
docs.securityonion.net/en/2.3/

Then follow along with our recent quick analysis blog posts:
blog.securityonion.net/search/

#cybersecurity #infosec #threathunting #incidentresponse #securityonion #malware

Last updated 3 years ago

Today's quick analysis with : FAKEBAT, REDLINE STEALER, and GOZI/ISFB/URSNIF pcap from 2023-02-03!

Thanks to @malware_traffic for sharing this pcap!

More screenshots:
blog.securityonion.net/2023/02




#malware #securityonion #infosec #infosecurity #threathunting #incidentresponse

Last updated 3 years ago

Want to learn more about with ?

Only 2 weeks left to register for this NEW 4-day pilot course in !

securityonionsolutions.com/tra



#threathunting #securityonion #columbiamd #infosec #cybersecurity #training

Last updated 3 years ago

Want the best hardware for ?

Check out our hardware appliances at:
securityonionsolutions.com/har

#securityonion

Last updated 3 years ago

If your Security Onion install is still on Ubuntu 18.04 you should upgrade soon as support ends in April. Here's a guide from on how to do so:
blog.securityonion.net/2023/02

#securityonion #ubuntu1804 #update #eol #endoflife #april #ubuntu #zeek #blueteam

Last updated 3 years ago

Want to learn more about with ?

Make sure you sign up for our upcoming 4-day pilot course in !

securityonionsolutions.com/tra

#threathunting #securityonion #columbiamd

Last updated 3 years ago

Frederick Theilig · @fmtheilig
4 followers · 17 posts · Server fosstodon.org

Looking for documentation?

It's built into our web interface for 2.3.210 but you can also find it online at:
securityonion.net/docs

#securityonion

Last updated 3 years ago

Looking for a fun project? πŸ˜€

Want to practice your πŸ” and skills?

Install πŸ§…2.3.210 in a VM:
docs.securityonion.net/en/2.3/

Then follow along with our recent quick analysis blog posts:
blog.securityonion.net/search/

#cybersecurity #threathunting #incidentresponse #securityonion #malware

Last updated 3 years ago

The Uberduck · @uberduck
53 followers · 177 posts · Server hachyderm.io

@train I haven't used it explicitly for this purpose yet, but might be an option.

std_disclaimer.h:
This opinion is mine and does not reflect the views of my employer.

#securityonion

Last updated 3 years ago

ICYMI, we've got some great new features coming in 2.4 and there are some important changes to be aware of!

blog.securityonion.net/2023/02

#securityonion

Last updated 3 years ago

Like ?

If you haven't already, please click the star on our github repo!

github.com/Security-Onion-Solu

#securityonion

Last updated 3 years ago

Want the best hardware for ?

Check out our hardware appliances at:
securityonionsolutions.com/har

#securityonion

Last updated 3 years ago