Please let us know if there are other topics you'd like us to cover in future videos!
Friday, August 28, 2020
Security Onion 2.1 (RC2), Import Node, and so-import-pcap!
Please let us know if there are other topics you'd like us to cover in future videos!
Monday, August 24, 2020
Security Onion 2.1 (Release Candidate 2) Available for Testing!
In 2018, Security Onion Solutions started working on the next major version of Security Onion, code-named Hybrid Hunter:
https://blog.securityonion.net/2018/11/security-onion-hybrid-hunter-101-tech.html
We recently dropped the Hybrid Hunter code name and announced 2.0 (RC1). Today, we are proud to release Security Onion 2.1 (Release Candidate 2)! It has some amazing new features and improvements!
One new feature in this release is that the installer now includes a new option for a dedicated import node. An import node is a single standalone box that runs just enough components to be able to import a pcap using so-import-pcap. When you run so-import-pcap, it analyzes the pcap using Suricata and Zeek and the resulting logs are picked up by Filebeat and sent to Elasticsearch where they are parsed and indexed. You can then view those logs in Security Onion Console (SOC). All this can be done in a minimal virtual machine with only 4GB RAM! For screenshots of the new import node, see the Screenshot Tour at the bottom of this blog post.
Another new feature that you'll see in the Screenshot Tour is that our new Hunt interface is better than ever! It now dynamically updates the columns in the bottom data table based on the actual data type that you're looking at. For example, if you're looking at DNS logs, Hunt will show columns that are relevant to DNS logs like the DNS query, type, and response code. Additionally, you'll notice that where field values used to have two magnifying glass icons (one to include the value in the search and the other to exclude the value from the search), there is now a third magnifying glass icon. This new icon starts a new search for just the value itself.
Release Candidate
This is our second Release Candidate for the new 2.x platform, so we're getting closer to a final release, but we're not quite there yet. Please be reminded of the usual pre-release warnings and disclaimers:
- If this breaks your system, you get to keep both pieces!
- This is a work in progress and is in constant flux.
- This configuration may change drastically over time leading up to the final release.
- Do NOT run this on a system that you care about!
- Do NOT run this on a system that has data that you care about!
- This script should only be run on a TEST box with TEST data!
- Use of this script may result in nausea, vomiting, or a burning sensation.
Documentation
We've started migrating our documentation to 2.1:
https://docs.securityonion.net/en/2.1/
However, this is a work in progress and some documentation may be missing or incorrect. Please let us know if you notice any issues.
Existing Installations
If you have an existing 2.0 (RC1) installation, please see the soup page on our documentation site:
https://docs.securityonion.net/en/2.1/soup.html
New Installations
If you want to do a new installation, please review the 2.1 documentation and then you can find instructions here:
https://docs.securityonion.net/en/2.1/download.html
Questions or Problems
If you have questions or problems, please see:
https://docs.securityonion.net/en/2.1/community-support.html
Known Issues
https://docs.securityonion.net/en/2.1/release-notes.html#known-issues
Changes from Previous Releases
https://docs.securityonion.net/en/2.1/release-notes.html#changes
Lots of love went into this release!
Special thanks to all our folks working so hard to make this release happen!
- Josh Brower
- Jason Ertel
- Wes Lambert
- Josh Patterson
- Mike Reeves
- Bryant Treacle
- William Wernert
Screenshot Tour
The screenshots below show the new Import node running in a minimal VM with only 4GB RAM!
Thursday, August 20, 2020
Security Onion 16.04.7.1 ISO image now available featuring Zeek 3.0.8, Snort 2.9.16.1, Elastic 6.8.11, CyberChef 9.21.0, and more!
Our Security Onion 16.04.7.1 ISO image is now available!
Major Changes Since Last ISO Image
- Zeek 3.0.8
- Snort 2.9.16.1
- Elastic 6.8.11
- CyberChef 9.21.0
Thanks
Thanks to Bryant Treacle and Chris Morgret for testing this ISO image!
Package Updates
This release also includes the following updated packages:
pinguybuilder - 20180514-1ubuntu1securityonion24
These packages resolve the following issues:
pinguybuilder: increment version to 16.04.7.1 #1772
https://github.com/Security-Onion-Solutions/security-onion/issues/1772
Issues Resolved
For a list of all issues resolved in this release, please see:
https://github.com/Security-Onion-Solutions/security-onion/projects/13
Release Notes
For more information about this release, please see:
https://securityonion.net/docs/release-notes.html
Installation Guide
We've updated the Installation guide to reflect the download locations for the new ISO image:
https://securityonion.net/docs/installation.html
Existing Deployments
If you have existing 16.04 installations, there is no need to download the new ISO image. You can simply continue using our standard update process to install updated packages as they are made available:
https://securityonion.net/docs/Upgrade
If you have existing installations of Security Onion 14.04, you can upgrade from 14.04 to 16.04:
https://securityonion.net/docs/upgrading-from-14.04-to-16.04.html
Documentation
You can find our documentation here:
https://securityonion.net/docs
Also, we're now offering a printed copy of our official documentation with foreword by Richard Bejtlich and proceeds going to Rural Technology Fund:
https://securityonion.net/book
Support
Need support? Please see:
https://securityonion.net/docs/Support
Training
Security Onion Solutions is the only official authorized training provider for Security Onion. For more information about our training classes, please see:
https://securityonionsolutions.com
Appliances
We also offer hardware appliances! For more information, please see:
https://securityonionsolutions.com
Thanks!
Wednesday, August 19, 2020
CyberChef 9.21.0 now available for Security Onion 16.04!
The following package is now available for Security Onion 16.04:
securityonion-web-page - 20141015-0ubuntu0securityonion108
This package resolves the following issues:
CyberChef 9.21.0 #1771
https://github.com/Security-Onion-Solutions/security-onion/issues/1771
Update docs and cheat sheet for 16.04.7.1 #1773
https://github.com/Security-Onion-Solutions/security-onion/issues/1773
Thanks
Thanks to the CyberChef team for CyberChef 9.21.0!
Thanks to Chris Morgret for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/docs/Upgrade
Support
Need support? Please see:
https://securityonion.net/docs/Support
Documentation
We've got a new documentation site! Please let us know if anything needs to be updated:
https://securityonion.net/docs
Also, we're now offering a printed copy of our official documentation with foreword by Richard Bejtlich and proceeds going to Rural Technology Fund:
https://securityonion.net/book
Training
Security Onion Solutions is the only official authorized training provider for Security Onion. For more information about our training classes, please see:
https://securityonionsolutions.com
Appliances
We also offer hardware appliances! For more information, please see:
https://securityonionsolutions.com
Thanks!
Tuesday, August 18, 2020
Snort 2.9.16.1 now available for Security Onion 16.04!
The following package is now available for Security Onion 16.04:
securityonion-snort - 2.9.16.1-1ubuntu1securityonion1
This package resolves the following issue:
Snort 2.9.16.1 #1780
https://github.com/Security-Onion-Solutions/security-onion/issues/1780
Thanks
Thanks to Cisco for Snort 2.9.16.1!
Thanks to Chris Morgret for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/docs/Upgrade
Support
Need support? Please see:
https://securityonion.net/docs/Support
Documentation
We've got a new documentation site! Please let us know if anything needs to be updated:
https://securityonion.net/docs
Also, we're now offering a printed copy of our official documentation with foreword by Richard Bejtlich and proceeds going to Rural Technology Fund:
https://securityonion.net/book
Training
Security Onion Solutions is the only official authorized training provider for Security Onion. For more information about our training classes, please see:
https://securityonionsolutions.com
Appliances
We also offer hardware appliances! For more information, please see:
https://securityonionsolutions.com
Thanks!
Thursday, August 6, 2020
Security Onion 2.0 RC1: so-import-pcap is back!
Please let us know if there are other topics you'd like us to cover in future videos!
Thursday, July 30, 2020
Security Onion 2.0.3 RC1 Available for Testing!
Zeek 3.0.8 now available for Security Onion 16.04!
Wednesday, July 29, 2020
Elastic Stack 6.8.11 now available for Security Onion 16.04!
Friday, July 24, 2020
Security Onion 2.0.2 RC1 Available for Testing!
Thursday, July 23, 2020
Security Update for Security Onion 2.0 RC1
UPDATE 2020/07/23 4:53 PM
Looks like the sensor interval fix for distributed deployments introduced a regression for other installation types. We're working on this issue now:
https://github.com/Security-Onion-Solutions/securityonion/issues/1089
UPDATE 2020/07/24 12:14 PM
We've fixed the regression in 2.0.2:
https://blog.securityonion.net/2020/07/security-onion-202-rc1-available-for.html
Wednesday, July 22, 2020
Security Onion Documentation Changes
- upgraded to a paid ReadTheDocs subscription to remove third party ads
- moved docs to custom domain https://docs.securityonion.net
- created separate versions for traditional 16.04 and new 2.0:
Tuesday, July 21, 2020
Security Onion 2.0 Release Candidate 1 (RC1) Available for Testing!
- If this breaks your system, you get to keep both pieces!
- This is a work in progress and is in constant flux.
- This configuration may change drastically over time leading up to the final release.
- Do NOT run this on a system that you care about!
- Do NOT run this on a system that has data that you care about!
- This script should only be run on a TEST box with TEST data!
- Use of this script may result in nausea, vomiting, or a burning sensation.
Documentation
- Re-branded 2.0 to give it a fresh look
- All documentation has moved to our docs site
- soup is alive! Note: This tool only updates Security Onion components. Please use the built-in OS update process to keep the OS and other components up to date.
- so-import-pcap is back! See the so-import-pcap docs here.
- Fixed issue with so-features-enable
- Users can now pivot to PCAP from Suricata alerts
- ISO install now prompts users to create an admin/sudo user instead of using a default account name
- The web email & password set during setup is now used to create the initial accounts for TheHive, Cortex, and Fleet
- Fixed issue with disk cleanup
- Changed the default permissions for /opt/so to keep non-priviledged users from accessing salt and related files
- Locked down access to certain SSL keys
- Suricata logs now compress after they roll over
- Users can now easily customize shard counts per index
- Improved Elastic ingest parsers including Windows event logs and Sysmon logs shipped with WinLogbeat and Osquery (ECS)
- Elastic nodes are now “hot” by default, making it easier to add a warm node later
- so-allow now runs at the end of an install so users can enable access right away
- Alert severities across Wazuh, Suricata and Playbook (Sigma) have been standardized and copied to event.severity:
1-Low / 2-Medium / 3-High / 4-Critical - Initial implementation of alerting queues:
- Low & Medium alerts are accessible through Kibana & Hunt
- High & Critical alerts are accessible through Kibana, Hunt and sent to TheHive for immediate analysis
- ATT&CK Navigator is now a statically-hosted site in the nginx container
- Playbook
- All Sigma rules in the community repo (500+) are now imported and kept up to date
- Initial implementation of automated testing when a Play’s detection logic has been edited (i.e., Unit Testing)
- Updated UI Theme
- Once authenticated through SOC, users can now access Playbook with analyst permissions without login
- Kolide Launcher has been updated to include the ability to pass arbitrary flags - new functionality sponsored by SOS
- Fixed issue with Wazuh authd registration service port not being correctly exposed
- Added option for exposure of Elasticsearch REST API (port 9200) to so-allow for easier external querying/integration with other tools
- Added option to so-allow for external Strelka file uploads (e.g., via strelka-fileshot)
- Added default YARA rules for Strelka – default rules are maintained by Florian Roth and pulled from https://github.com/Neo23x0/signature-base
- Added the ability to use custom Zeek scripts
- Renamed “master server” to “manager node”
- Improved unification of Zeek and Strelka file data
Bryant Treacle
![]() |
| ISO Boot Menu |
![]() |
| OS account creation |
![]() |
| Web account creation |
![]() |
| Logging into Security Onion Console (SOC) |
![]() |
| Security Onion Console (SOC) |
![]() |
| Hunt |
![]() |
| Pivot to PCAP from Hunt or Kibana |
![]() |
| SOC Sensor Management |
![]() |
| Downloads page includes links to Winlogbeat and osquery packages |
![]() |
| SOC User Management |
![]() |
| Kibana |
![]() |
| Grafana |
![]() |
| CyberChef |
![]() |
| Playbook |
![]() |
| Fleet |
![]() |
| TheHive |
![]() |
| ATT&CK Navigator |
Wednesday, July 1, 2020
Security Onion Hybrid Hunter 1.4.1 Available for Testing!
Monday, June 29, 2020
Security Onion Hybrid Hunter Beta 3, Community ID, and Sysmon!
Please let us know if there are other topics you'd like us to cover in future videos!
securityonion-sostat - 20120722-0ubuntu0securityonion145 now available for Security Onion!
Wednesday, June 17, 2020
Security Onion Hybrid Hunter 1.4.0 - Beta 3 Available for Testing!
![]() |
| Hunt now shows Community ID by default and includes a new Auto Hunt feature |
- Complete overhaul of the way we handle custom and default settings and data. You will now see a default and local directory under the saltstack directory. All customizations are stored in local.
- The way firewall rules are handled has been completely revamped. This will allow the user to customize firewall rules much easier.
- Users can now change their own password in SOC.
- Hunt now allows users to enable auto-hunt. This is a toggle which, when enabled, automatically submits a new hunt when filtering, grouping, etc.
- Title bar now reflects current Hunt query. This will assist users in locating a previous query from their browser history.
- Zeek 3.0.7
- Elastic 7.7.1
- Suricata can now be used for meta data generation.
- Suricata eve.json has been moved to /nsm to align with storage of other data.
- Suricata will now properly rotate its logs.
- Grafana dashboards now work properly in standalone mode.
- Kibana Dashboard updates including osquery, community_id.
- New Elasticsearch Ingest processor to generate community_id from any log that includes the required fields.
- Community_id generated for additional logs: Zeek HTTP/SMTP, Sysmon shipped with Osquery or Winlogbeat.
- Major streamlining of Fleet setup & configuration - no need to run a secondary setup script anymore.
- Fleet Standalone node now includes the ability to set a FQDN to point osquery endpoints to.
- Distributed installs now support ingesting Windows Eventlogs via Winlogbeat - includes full parsing support for Sysmon.
- SOC Downloads section now includes a link to the supported version of Winlogbeat.
- Basic syslog ingestion capability now included.
- Elasticsearch index name transition fixes for various components.
- Updated URLs for pivot fields in Kibana.
- Instances of hive renamed to thehive.
- When prompted for hostname, please only enter the hostname itself and NOT a fully qualified domain name! There should be no dots or other special characters.
- The Hunt feature is currently considered "Preview" and although very useful in its current state, not everything works. We wanted to get this out as soon as possible to get the feedback from you! Let us know what you want to see! Let us know what you think we should call it!
- You cannot pivot to PCAP from Suricata alerts in Kibana or Hunt.
- Navigator is currently not working when using hostname to access SOC. IP mode works correctly.
- Due to the move to ECS, the current Playbook plays may not alert correctly at this time.
- The osquery MacOS package does not install correctly.
Thursday, June 11, 2020
Zeek 3.0.7 now available for Security Onion!
Monday, June 8, 2020
Elastic 6.8.10 now available for Security Onion!
Friday, May 29, 2020
Our New Security Onion Hunt Interface!
Please let us know if there are other topics you'd like us to cover in future videos!
Thursday, May 28, 2020
Community Webinars featuring Security Onion
UPDATE 2020/06/05 - The follow-up Zeek webinar has been confirmed and added to the list below!
Thur, June 11, 2020
Ask The Zeeksperts (follow up to previous Zeek From Home webinar)
https://corelight.zoom.us/webinar/register/5915913046898/WN_Bc8HGitBQImZU3B5vCtAow
Wednesday, May 20, 2020
Security Onion Hybrid Hunter 1.3.0 - Beta 2 Available for Testing!
https://blog.securityonion.net/2018/11/security-onion-hybrid-hunter-101-tech.html
Today we are proud to release Security Onion "Hybrid Hunter” 1.3.0 AKA Beta 2 and it has some amazing new features and improvements!
The biggest new feature in this release is a brand new web interface for hunting through your logs. Once you've logged into the Security Onion Console, click the Hunt link and then choose one of the many pre-defined queries in the drop-down or write your own using Onion Query Language (OQL). OQL is based on standard Lucene query syntax and allows you to optionally specify one or more fields to group by. For a few examples, check out the screenshot tour at the bottom of this blog post. This is the first public release of this new interface and we are firm believers in "release early, release often". We have lots of ideas for the future of this tool, but we want to hear your ideas as well.
This release also includes a new Standalone installation option that runs all of the major components on one box. It's similar to Eval mode but has more capabilities beyond just doing a quick evaluation.
Finally, this update includes lots of improvements for parsers, visualizations, dashboards, and Elastic Common Schema (ECS) support. We've done lots of testing along the way and we're ready for you to do some testing and let us know what you think!
To read more and download Hybrid Hunter, please see:
https://github.com/Security-Onion-Solutions/securityonion-saltstack/wiki/ISO
https://github.com/Security-Onion-Solutions/securityonion-saltstack/blob/master/README.md
If you have any questions about Hybrid Hunter, please post a message on our reddit community and prefix the title with [Hybrid Hunter]!
https://www.reddit.com/r/securityonion/
Major Highlights in this Release
Changes:
- New Feature: Codename: "Onion Hunt". Select Hunt from the menu and start hunting down your adversaries!
- Improved ECS support.
- Complete refactor of the setup to make it easier to follow.
- Improved setup script logging to better assist on any issues.
- Setup now checks for minimal requirements during install.
- Updated Cyberchef to version 9.20.3.
- Updated Elastalert to version 0.2.4 and switched to alpine to reduce container size.
- Updated Redis to 5.0.9 and switched to alpine to reduce container size.
- Updated Salt to 2019.2.5
- Updated Grafana to 6.7.3.
- Zeek 3.0.6
- Suricata 4.1.8
- Fixes so-status to now display correct containers and status.
- local.zeek is now controlled by a pillar instead of modifying the file directly.
- Renamed so-core to so-nginx and switched to alpine to reduce container size.
- Playbook now uses MySQL instead of SQLite.
- Sigma rules have all been updated.
- Kibana dashboard improvements for ECS.
- Fixed an issue where geoip was not properly parsed.
- ATT&CK Navigator is now it's own state.
- Standalone mode is now supported.
- Mastersearch previously used the same Grafana dashboard as a Search node. It now has its own dashboard that incorporates panels from the Master node and Search node dashboards.
Known Issues:
- The Hunt feature is currently considered "Preview" and although very useful in its current state, not everything works. We wanted to get this out as soon as possible to get the feedback from you! Let us know what you want to see! Let us know what you think we should call it!
- You cannot pivot to PCAP from Suricata alerts in Kibana or Hunt.
- Updating users via the SOC ui is known to fail. To change a user, delete the user and re-add them.
- Due to the move to ECS, the current Playbook plays may not alert correctly at this time.
- The osquery MacOS package does not install correctly.
Thanks
Lots of love went into this release!
Special thanks to all our folks working so hard to make this release happen!
- Josh Brower
- Jason Ertel
- Wes Lambert
- Josh Patterson
- Mike Reeves
- William Wernert
Screenshots
Search This Blog
Featured Post
Security Onion 3.3.0 Hotfix 20260911 Now Available!
Earlier this week, we released Security Onion 3.3.0: https://blog.securityonion.net/2026/09/security-onion-330-now-available.html Today we a...
Popular Posts
-
Security Onion 3.0.0 is now available and includes a new and improved interface, updated components, and many quality of life improvements! ...
-
Security Onion 2.4.180 is now available and includes several new features, updated components, and many quality of life improvements! For Se...
-
For Security Onion Pro customers, we've made major improvements for our popular new Onion AI Assistant. Many folks have been asking for ...
Blog Archive
- September 2026 (2)
- August 2026 (2)
- July 2026 (2)
- May 2026 (6)
- April 2026 (4)
- March 2026 (5)
- January 2026 (3)
- December 2025 (5)
- November 2025 (2)
- October 2025 (2)
- September 2025 (3)
- August 2025 (4)
- July 2025 (3)
- June 2025 (3)
- May 2025 (5)
- April 2025 (2)
- March 2025 (7)
- February 2025 (5)
- January 2025 (11)
- December 2024 (3)
- November 2024 (1)
- October 2024 (9)
- September 2024 (16)
- August 2024 (3)
- July 2024 (7)
- June 2024 (5)
- May 2024 (2)
- April 2024 (7)
- March 2024 (5)
- February 2024 (3)
- January 2024 (3)
- December 2023 (15)
- November 2023 (27)
- October 2023 (18)
- September 2023 (3)
- August 2023 (8)
- July 2023 (4)
- June 2023 (3)
- May 2023 (2)
- April 2023 (4)
- March 2023 (4)
- February 2023 (5)
- January 2023 (3)
- December 2022 (5)
- November 2022 (2)
- October 2022 (9)
- September 2022 (3)
- August 2022 (8)
- July 2022 (7)
- June 2022 (9)
- May 2022 (14)
- April 2022 (7)
- March 2022 (6)
- February 2022 (11)
- January 2022 (12)
- December 2021 (19)
- November 2021 (25)
- October 2021 (22)
- September 2021 (23)
- August 2021 (30)
- July 2021 (13)
- June 2021 (4)
- May 2021 (3)
- April 2021 (4)
- March 2021 (7)
- February 2021 (5)
- January 2021 (4)
- December 2020 (13)
- November 2020 (5)
- October 2020 (12)
- September 2020 (3)
- August 2020 (6)
- July 2020 (8)
- June 2020 (5)
- May 2020 (9)
- April 2020 (11)
- March 2020 (7)
- February 2020 (4)
- January 2020 (1)
- December 2019 (6)
- November 2019 (4)
- October 2019 (8)
- September 2019 (7)
- August 2019 (7)
- July 2019 (4)
- June 2019 (7)
- May 2019 (20)
- April 2019 (8)
- March 2019 (7)
- February 2019 (7)
- January 2019 (12)
- December 2018 (12)
- November 2018 (13)
- October 2018 (10)
- September 2018 (4)
- August 2018 (16)
- July 2018 (11)
- June 2018 (13)
- May 2018 (4)
- April 2018 (11)
- March 2018 (9)
- February 2018 (10)
- January 2018 (9)
- December 2017 (7)
- November 2017 (7)
- October 2017 (9)
- September 2017 (4)
- August 2017 (7)
- July 2017 (5)
- June 2017 (8)
- May 2017 (4)
- April 2017 (2)
- March 2017 (1)
- February 2017 (3)
- January 2017 (15)
- December 2016 (9)
- November 2016 (3)
- October 2016 (5)
- September 2016 (13)
- August 2016 (12)
- July 2016 (10)
- June 2016 (7)
- May 2016 (7)
- April 2016 (7)
- March 2016 (10)
- February 2016 (13)
- January 2016 (10)
- December 2015 (1)
- November 2015 (1)
- October 2015 (3)
- September 2015 (5)
- August 2015 (7)
- July 2015 (7)
- June 2015 (12)
- May 2015 (6)
- April 2015 (6)
- March 2015 (6)
- February 2015 (10)
- January 2015 (11)
- December 2014 (5)
- November 2014 (3)
- October 2014 (6)
- September 2014 (20)
- August 2014 (7)
- July 2014 (10)
- June 2014 (10)
- May 2014 (3)
- April 2014 (9)
- March 2014 (6)
- February 2014 (9)
- January 2014 (8)
- December 2013 (5)
- November 2013 (2)
- October 2013 (7)
- September 2013 (5)
- August 2013 (7)
- July 2013 (9)
- June 2013 (7)
- May 2013 (11)
- April 2013 (3)
- March 2013 (3)
- February 2013 (3)
- January 2013 (3)
- December 2012 (3)
- November 2012 (1)
- October 2012 (1)
- September 2012 (1)
- August 2012 (2)
- May 2012 (4)
- April 2012 (6)
- March 2012 (8)
- February 2012 (4)
- January 2012 (13)
- December 2011 (9)
- November 2011 (8)
- October 2011 (8)
- September 2011 (8)
- July 2011 (4)
- June 2011 (5)
- May 2011 (2)
- April 2011 (1)
- February 2011 (1)
- January 2011 (11)
- November 2010 (4)
- October 2010 (8)
- August 2010 (1)
- July 2010 (2)
- June 2010 (1)
- May 2010 (1)
- April 2010 (2)
- February 2010 (3)
- January 2010 (1)
- September 2009 (1)
- August 2009 (3)
- July 2009 (4)
- June 2009 (3)
- May 2009 (1)
- April 2009 (8)
- February 2009 (1)
- January 2009 (9)
- November 2008 (2)
- October 2008 (4)
- September 2008 (3)










































