Friday, September 15, 2017

Elastic Stack Alpha Release and Security Onion 14.04.5.3 ISO Image!

UPDATED 2018/04/09! We've released a newer version!
https://blog.securityonion.net/2018/04/security-onion-elastic-stack-general.html

We recently announced the first three technology previews of the Elastic stack on Security Onion:
http://blog.securityonion.net/2017/03/towards-elk-on-security-onion.html
http://blog.securityonion.net/2017/06/towards-elastic-on-security-onion.html
http://blog.securityonion.net/2017/07/towards-elastic-on-security-onion.html

We're excited to announce that our Elastic stack integration has now reached Alpha Release!  Part of this Alpha release is a new 14.04.5.3 ISO image that contains these Alpha components.  This ISO image contains all the latest Ubuntu and Security Onion updates as of September 5, 2017!

Highlights of this Alpha Release

  • Upgraded from Elastic 5.5.0 to 5.5.2
  • All Elastic config files and scripts are now in a new package called securityonion-elastic (securityonion_elastic.sh from previous tech previews is no longer necessary)
  • In Kibana, the Squert and Logout links have been moved to the side panel
  • Kibana search now defaults to last 24 hours
  • Lots of cleanup and fixes
  • Elastic distributed deployments are implemented using cross cluster search
Distributed Deployment with Master Server and Two Sensors

Video
You can learn more about this release by watching the State of the Onion talk at Security Onion Conference 2017.

Issues Resolved

Issue 1071: 14.04.5.3 ISO image
https://github.com/Security-Onion-Solutions/security-onion/issues/1071

Issue 1095: Elastic Stack Alpha Release
https://github.com/Security-Onion-Solutions/security-onion/issues/1095

Thanks
This new ISO image has been tested by Wes Lambert and Phil Plantamura.  Thanks, guys!

New Installations
I've updated the Verify_ISO page for the new ISO image:
https://github.com/Security-Onion-Solutions/security-onion/blob/master/Verify_ISO.md

Please remember to verify the signature of the downloaded ISO image using the instructions on that page.

Please note! This ISO image includes the EXPERIMENTAL Elastic stack!

The Elastic components are included in the ISO image and Setup gives you an option of Stable Setup (ELSA) or Experimental Setup (Elastic). If you do not want to try the new Elastic stack, you can choose Stable Setup.  If you choose Experimental Setup, the usual disclaimers and warnings apply!

  • Experimental Setup is ALPHA, BLEEDING EDGE, and TOTALLY UNSUPPORTED!
  • If this breaks your system, you get to keep both pieces!
  • This is a work in progress and is in constant flux.
  • This is intended to build a quick prototype proof of concept so you can see what our ultimate Elastic configuration might look like.  This configuration will change drastically over time leading up to the final release.
  • Do NOT run this on a system that you care about!
  • Do NOT run this on a system that has data that you care about!
  • This should only be run on a TEST box with TEST data!
  • Experimental Setup may result in nausea, vomiting, or a burning sensation.

For more about this Elastic Alpha release, please see https://securityonion.net/wiki/elastic and the Screenshot tour at the bottom of this blog post.

Please note the following minimum hardware requirements for the Elastic stack:

  • 2 CPU cores
  • 8GB RAM

If you would prefer an ISO image with no Elastic components at all, you have a few options:



Existing Deployments
If you have existing installations based on a previous 14.04 ISO image, there is no need to download the new ISO image.  You can simply continue using our standard update process to install updated packages as they are made available:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Release Notes
For more information about this release, please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Security-Onion-14.04-Release-Notes

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
We have a 4-day Security Onion training class coming up in San Antonio, Texas!  For this and other training options, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Screenshot Tour
Experimental Setup configures the Elastic Stack

Choosing Experimental Setup displays Warnings and Disclaimers

Experimental Setup includes Evaluation Mode and Production Mode

Network Interface Selection

Creating Username

Creating Password

Confirming Password

Confirming Options

Squert and Logout links have been moved to Kibana Side Panel

Home (Overview) Dashboard

Alert Data - Bro Notices

Alert Data - ElastAlert

Alert Data - HIDS

Alert Data - NIDS

Bro Hunting - Connections

Bro Hunting - DCE/RPC

Bro Hunting - DHCP

Bro Hunting - DNP3

Bro Hunting - DNS 
Bro Hunting - Files



Bro Hunting - FTP

Bro Hunting - HTTP

Bro Hunting - Intel

Bro Hunting - IRC

Bro Hunting - Kerberos

Bro Hunting - Modbus

Bro Hunting - MySQL

Bro Hunting - NTLM

Bro Hunting - PE

Bro Hunting - RADIUS

Bro Hunting - RDP

Bro Hunting - RFB

Bro Hunting - SIP

Bro Hunting - SMB

Bro Hunting - SMTP

Bro Hunting - SNMP

Bro Hunting - Software

Bro Hunting - SSH

Bro Hunting - SSL

Bro Hunting - Syslog

Bro Hunting - Tunnels

Bro Hunting - Weird

Bro Hunting - X.509

Host Hunting - Autoruns

Host Hunting - OSSEC

Host Hunting - Sysmon

Other - Firewall

Other - Stats

Other - Syslog
Distributed Deployment with Master and 2 Sensors using Cross Cluster Search
UPDATE 2017/09/18 - Added link to State of the Onion talk at Security Onion Conference 2017

Tuesday, September 5, 2017

securityonion-setup - 20120912-0ubuntu0securityonion245 now available for Security Onion!

The following package is now available:
securityonion-setup - 20120912-0ubuntu0securityonion245

This package should resolve the following issues:

setup: add EXPERIMENTAL option for Elastic #1128
https://github.com/Security-Onion-Solutions/security-onion/issues/1128

PLEASE NOTE!  This EXPERIMENTAL option will only be offered if the EXPERIMENTAL securityonion-elastic package is installed.  If you install the EXPERIMENTAL securityonion-elastic package and then choose this EXPERIMENTAL option, the usual disclaimers and warnings apply!

  • This EXPERIMENTAL software is PRE-ALPHA, BLEEDING EDGE, and TOTALLY UNSUPPORTED!
  • If this breaks your system, you get to keep both pieces!
  • This is a work in progress and is in constant flux.
  • This is intended to build a quick prototype proof of concept so you can see what our ultimate Elastic configuration might look like.  This configuration will change drastically over time leading up to the final release.
  • Do NOT run this on a system that you care about!
  • Do NOT run this on a system that has data that you care about!
  • This should only be run on a TEST box with TEST data!
  • Use of this script may result in nausea, vomiting, or a burning sensation.


Thanks
Thanks to Wes Lambert for testing the new package!

Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference 2017 will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
We have a 4-day Security Onion training class right before the Security Onion Conference in Augusta GA.  For this and other training options, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Thursday, August 31, 2017

securityonion-sostat - 20120722-0ubuntu0securityonion74 now available for Security Onion!

The following package is now available:
securityonion-sostat - 20120722-0ubuntu0securityonion74

This package should resolve the following issues:

Issue 928: soup: if snort/suricata/bro updated, remind user to
re-apply local changes
https://github.com/Security-Onion-Solutions/security-onion/issues/928

Issue 1072: soup: include reference to blog.securityonion.net
https://github.com/Security-Onion-Solutions/security-onion/issues/1072

Issue 1108: soup: handle situations where apt prompts to keep/replace file
https://github.com/Security-Onion-Solutions/security-onion/issues/1108

Issue 1124: soup: update docker images if enabled
https://github.com/Security-Onion-Solutions/security-onion/issues/1124

Issue 1125: sostat: report on docker images if enabled
https://github.com/Security-Onion-Solutions/security-onion/issues/1125

Thanks
Thanks to Wes Lambert and Phil Plantamura for testing the new package!

Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference 2017 will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
We have a 4-day Security Onion training class right before the Security Onion Conference in Augusta GA.  For this and other training options, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Wednesday, August 30, 2017

New ELSA Packages Available for Security Onion

I've built new ELSA packages and the new package versions are as follows:
securityonion-elsa - 1205chartsjsd3-1ubuntu1securityonion10
securityonion-elsa-extras - 20151011-1ubuntu1securityonion56

These new packages should resolve the following issues:

Issue 1074: securityonion-elsa-extras: add 5140 parser
https://github.com/Security-Onion-Solutions/security-onion/issues/1074

Issue 1075: securityonion-elsa-extras: add storage calculator
https://github.com/Security-Onion-Solutions/security-onion/issues/1075

Issue 1076: securityonion-elsa-extras: refactor securityonion-elsa-reset
https://github.com/Security-Onion-Solutions/security-onion/issues/1076

Issue 1080: securityonion-elsa-extras: add delaycompress for elsa logs
https://github.com/Security-Onion-Solutions/security-onion/issues/1080

Issue 1122: securityonion-elsa: remove 300px limitation
https://github.com/Security-Onion-Solutions/security-onion/issues/1122

Thanks
Thanks to the following for submitting pull requests!
Brian Kellogg
Wes Lambert
Github user "4A61736F6E"
Pete Nelson
Phil Plantamura
Thanks to Wes Lambert and Phil Plantamura for testing the new packages!

Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference 2017 will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
We have a 4-day Security Onion training class right before the Security Onion Conference in Augusta GA.  For this and other training options, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Tuesday, August 29, 2017

NetworkMiner 2.2 now available for Security Onion!

NetworkMiner 2.2 was released recently:
https://netresec.com/?b=17888CB

The following package is now available:
securityonion-networkminer - 20170828-1ubuntu1securityonion1

This package should resolve the following issues:

Issue 1127: NetworkMiner 2.2
https://github.com/Security-Onion-Solutions/security-onion/issues/1127

Thanks
Thanks to Erik Hjelmvik for NetworkMiner 2.2!
Thanks to Wes Lambert and Erik Hjelmvik for testing the new package!

Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference 2017 will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
We have a 4-day Security Onion training class right before the Security Onion Conference in Augusta GA.  For this and other training options, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Monday, August 21, 2017

securityonion-squert - 20161212-1ubuntu1securityonion14 now available for Security Onion!

The following package is now available:
securityonion-squert - 20161212-1ubuntu1securityonion14

This package should resolve the following issues:

Squert: comment search not working #1119
https://github.com/Security-Onion-Solutions/security-onion/issues/1119

Thanks
Thanks to GRSmith for the bug report!
Thanks to Wes Lambert for testing the new package!

Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference 2017 will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
We have a 4-day Security Onion training class right before the Security Onion Conference in Augusta GA.  For this and other training options, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Wednesday, August 16, 2017

4-day Security Onion Training is coming to San Antonio, TX!

Registration is now open for 4-day Security Onion training in San Antonio, TX!  For more details and to register, please see:
https://securityonionsolutions.com/onsitetraining

securityonion-nsmnow-admin-scripts - 20120724-0ubuntu0securityonion159 now available for Security Onion!

The following package is now available:
securityonion-nsmnow-admin-scripts - 20120724-0ubuntu0securityonion159

This package should resolve the following issues:

NSM: barnyard sending blank interface to syslog output #652
https://github.com/Security-Onion-Solutions/security-onion/issues/652

NSM: cron job to check if netsniff-ng is recording with a date other
than today #1117
https://github.com/Security-Onion-Solutions/security-onion/issues/1117

Thanks
Thanks to Kevin Branch and Wes Lambert for submitting pull requests!
Thanks to Kevin Branch and Wes Lambert for testing the new package!

Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
We have a 4-day Security Onion training class right before the Security Onion Conference in Augusta GA.  For this and other training options, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Thursday, August 3, 2017

Suricata 4.0.0 now available for Security Onion!

Suricata 4.0.0 was recently released:
https://suricata-ids.org/2017/07/27/suricata-4-0-released/

The following package is now available:
securityonion-suricata - 4.0.0-1ubuntu1securityonion1

This package should resolve the following issue:

Suricata 4.0.0 #1116
https://github.com/Security-Onion-Solutions/security-onion/issues/1116

Thanks
Thanks to the Suricata team for Suricata 4.0.0!
Thanks to Wes Lambert for testing the new package!

Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
We have a 4-day Security Onion training class right before the Security Onion Conference in Augusta GA.  For this and other training options, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Monday, July 31, 2017

securityonion-setup - 20120912-0ubuntu0securityonion237 now available for Security Onion!

The following package is now available:
securityonion-setup - 20120912-0ubuntu0securityonion237

This package should resolve the following issue:

Issue 1113: so-allow/disallow: fix wrong number of arguments error
https://github.com/Security-Onion-Solutions/security-onion/issues/1113

Thanks
Thanks to Wes Lambert for submitting the pull request and testing the new package!

Updating
These packages are now available in our stable repo.  Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
We have a 4-day Security Onion training class right before the Security Onion Conference in Augusta GA.  For this and other training options, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Friday, July 28, 2017

Towards Elastic on Security Onion: Technology Preview 3 (TP3)

UPDATED 2018/04/09! We've released a newer version!
https://blog.securityonion.net/2018/04/security-onion-elastic-stack-general.html

We recently announced the first two technology previews of the Elastic stack on Security Onion:
http://blog.securityonion.net/2017/03/towards-elk-on-security-onion.html
http://blog.securityonion.net/2017/06/towards-elastic-on-security-onion.html

We've made more progress, so it's time for our third technology preview (TP3)!

Changes from the last Technology Preview

  • upgraded from Elastic 5.4.0 to 5.5.0
  • added containers for ElastAlert, Curator, DomainStats, and FreqServer
  • each container logs to its own log directory in /var/log/
  • securityonion_elastic.sh now supports new installations in addition to upgrading ELSA installations
  • new and updated dashboards
  • added parsers for pfSense, sysmon, and autoruns logs
  • sostat now provides status for Elastic stack
  • Indicator dashboard now only searches the last 24 hours by default for better performance
Highlights of This Release




Endpoint Visibility - Autoruns

Endpoint Visibility - Autoruns (continued)
Endpoint Visibility - Autoruns (continued)
Endpoint Visibility - Sysmon
Endpoint Visibility - Sysmon (continued)
Firewall Logs

DNS Frequency Analysis

SSL Frequency Analysis

For more screenshots, please see the full Screenshot Tour at the end of this blog post.


Warnings and Disclaimers

  • This technology PREVIEW is PRE-ALPHA, BLEEDING EDGE, and TOTALLY UNSUPPORTED!
  • If this breaks your system, you get to keep both pieces!
  • This script is a work in progress and is in constant flux.
  • This script is intended to build a quick prototype proof of concept so you can see what our ultimate Elastic configuration might look like.  This configuration will change drastically over time leading up to the final release.
  • Do NOT run this on a system that you care about!
  • Do NOT run this on a system that has data that you care about!
  • This script should only be run on a TEST box with TEST data!
  • This script is only designed for standalone boxes and does NOT support distributed deployments.
  • Use of this script may result in nausea, vomiting, or a burning sensation.

Enough disclaimers?  Let's do this!

Hardware Requirements

Start with a disposable TEST VM with the following minimum requirements:

  • 2 CPU cores
  • 8GB RAM
  • 20GB virtual hard drive
  • (1) management interface with full Internet access
  • (1) sniffing interface (separate from management interface)

Choose ELSA Migration or New Installation

Previous technology previews used a script called securityonion_elsa2elastic.sh which only supported migrating from an existing ELSA installation.  That script is now deprecated.  This technology preview now uses a script called securityonion_elastic.sh which supports not only migrating from an existing ELSA installation but also configuring new installations.

Scenario #1 - Migrate from ELSA to Elastic (as in previous Technology Previews)

  • Install Security Onion 14.04.5.2 ISO image
  • Run through existing version of Setup choosing Evaluation Mode to enable ELSA
  • Download the script:

    wget https://raw.githubusercontent.com/Security-Onion-Solutions/elastic-test/master/securityonion_elastic.sh
  • Run the script with sudo privileges:

    sudo bash securityonion_elastic.sh
  • Please read through all the WARNINGS and DISCLAIMERS and ONLY proceed if you agree.
  • The script will take at least 10 minutes depending on the speed of your hardware and Internet connection. 
  • Proceed to the Kibana section below.


Scenario #2 - Fresh Elastic installation
  • Install Security Onion 14.04.5.2 ISO image
  • Download the script:

    wget https://raw.githubusercontent.com/Security-Onion-Solutions/elastic-test/master/securityonion_elastic.sh
  • Run the script with sudo privileges:

    sudo bash securityonion_elastic.sh
  • Please read through all the WARNINGS and DISCLAIMERS and ONLY proceed if you agree.
  • This will in turn download the Elastic components and then prompt you to run Setup.
  • Run through both phases of Setup (configure network interfaces, reboot, and then run Setup again choosing Evaluation Mode).
  • Once Setup has completed, create some test data:

    sudo so-test


Accessing Kibana
Once you've completed the migration or installation as described above, open the Chromium web browser and go to:

https://localhost/app/kibana

You should then see our new Security Onion login window.  Enter the same credentials that you use to login to Sguil/Squert.  This login window will provide single sign on for Kibana, Squert, and CapMe to allow seamless pivoting to full packet capture!

Once logged into Kibana, you will automatically start on our Overview dashboard and you will see links to other dashboards as well.  As you search through the data in Kibana, you should see Bro logs,  syslog, and Snort alerts.  Logstash should have parsed out most fields in most Bro logs and Snort alerts.  Notice that the search panels at the bottom of the dashboards display the source_ip and destination_ip fields with hyperlinks.  These hyperlinks will take you to a dashboard that will help you analyze the traffic relating to that particular IP address.  UID fields are also hyperlinked.  Clicking on a UID hyperlink will start a new Kibana search for that particular UID.  In the case of Bro UIDs this will show you all Bro logs related to that particular connection.  Each log entry also has an _id field that is hyperlinked.  This hyperlink will take you to CapMe, allowing you to request full packet capture for any arbitrary log type!  This assumes that the log is for tcp or udp traffic that was seen by Bro and Bro recorded it correctly in its conn.log.

Previously, in Squert and Sguil, you could pivot from an IP address to ELSA.  Those pivots have been removed and replaced with a pivot to Kibana.

For screenshots, please see the Screenshot Tour at the bottom of this post.

Thanks
Special thanks to Justin Henderson for his work on the domainstats and freqserver integration in this release!

More Information
For more information about our Elastic integration, please see the Elastic page on our Wiki:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Elastic

TODO
For the current TODO list, please see:
https://github.com/Security-Onion-Solutions/security-onion/issues/1095

Feedback
We're releasing this now because we want to get your feedback as early as possible in this project.  Please try it out and send your feedback to our mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists

What do you think?

What works well?

What needs to be improved?

Any questions or other comments?

Thanks in advance for any and all feedback!

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Need Security Onion Training?
We offer both onsite and online training (although please note that Elastic will not be added to training classes until we reach a stable release):
https://securityonionsolutions.com/onsitetraining
https://securityonionsolutions.com/ondemandtraining

Conference
Our annual Security Onion Conference will be Friday September 15, 2017:
https://securityonion.net/conference

Hope to see you there!

Screenshot Tour
Overview Dashboard


Bro Notices Dashboard 
HIDS Alerts Dashboard (OSSEC)



NIDS Alerts Dashboard (Snort/Suricata)

Bro Connections Dashboard

Bro DCE/RPC Dashboard

Bro DHCP Dashboard

Bro DNP3 Dashboard

Bro DNS Dashboard 
Bro Files Dashboard



Bro FTP Dashboard

Bro HTTP Dashboard

Bro Intel Dashboard

Bro IRC Dashboard

Bro Kerberos Dashboard

Bro Modbus Dashboard

Bro MySQL Dashboard

Bro NTLM Dashboard

Bro PE Dashboard

Bro RADIUS Dashboard

Bro RDP Dashboard

Bro RFB Dashboard

Bro SIP Dashboard

Bro SMB Dashboard

Bro SMTP Dashboard

Bro SNMP Dashboard

Bro Software Dashboard

Bro SSH Dashboard

Bro SSL Dashboard

Bro Tunnels Dashboard 
Bro Weird Dashboard



Bro X.509 Dashboard

Autoruns Dashboard

Autoruns Dashboard (continued)

Autoruns Dashboard (continued) 

OSSEC Logs Dashboard 
Sysmon Dashboard



Sysmon Dashboard (continued)

Firewall Dashboard (pfSense logs)

Stats Dashboard

UPDATED 2017/07/29 - Added hyperlinks to wiki pages for Elastic, Curator, DomainStats, ElastAlert, and FreqServer.

Monday, July 17, 2017

Suricata 3.2.3 now available for Security Onion!

Suricata 3.2.3 was recently released:
https://suricata-ids.org/2017/07/13/suricata-3-2-3-available/

The following package is now available:
securityonion-suricata - 3.2.3-1ubuntu1securityonion1

This package should resolve the following issue:

Suricata 3.2.3 #1112
https://github.com/Security-Onion-Solutions/security-onion/issues/1112

Thanks
Thanks to the Suricata team for Suricata 3.2.3!
Thanks to Wes Lambert for testing the new package!

Updating
These packages are now available in our stable repo.  Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
Need training?  Please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Monday, July 10, 2017

securityonion-setup - 20120912-0ubuntu0securityonion236 now available for Security Onion!

The following package is now available:
securityonion-setup - 20120912-0ubuntu0securityonion236

This package should resolve the following issue:

Issue 1111: so-allow analyst mode should add IP address to OSSEC whitelist
https://github.com/Security-Onion-Solutions/security-onion/issues/1111

Thanks
Thanks to Wes Lambert for submitting the pull request and testing the new package!

Updating
These packages are now available in our stable repo.  Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
Need training?  Please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Wednesday, July 5, 2017

Bro 2.5.1 now available for Security Onion!

Bro 2.5.1 was released recently:
http://blog.bro.org/2017/06/bro-251-released.html
https://www.bro.org/download/NEWS.bro.html
https://www.bro.org/download/CHANGES.bro.txt

The following packages are now available:

securityonion-bro - 2.5.1-1ubuntu1securityonion2
securityonion-bro-scripts - 20121004-0ubuntu0securityonion50

These new packages should resolve the following issues:

Issue 1109: Bro 2.5.1
https://github.com/Security-Onion-Solutions/security-onion/issues/1109

Issue 1052: Segmentation fault /opt/bro/bin/capstats
https://github.com/Security-Onion-Solutions/security-onion/issues/1052

Thanks
Thanks to Github user "bugcrash" for finding and reporting a segmentation fault in /opt/bro/bin/capstats!
Thanks to the Bro team for Bro 2.5.1!
Thanks to Wes Lambert for testing these new packages!

Updating
These packages are now available in our stable repo.  Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
Need training?  Please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Friday, June 30, 2017

securityonion-setup - 20120912-0ubuntu0securityonion234 now available for Security Onion!

The following package is now available:
securityonion-setup - 20120912-0ubuntu0securityonion234

This package should resolve the following issue:

Issue 1106: Update so-allow to allow apt-cacher-ng clients and add so-disallow
https://github.com/Security-Onion-Solutions/security-onion/issues/1106

Thanks
Thanks to Wes Lambert for submitting the pull request and testing the new package!

Updating
These packages are now available in our stable repo.  Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
Need training?  Please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Thursday, June 29, 2017

securityonion-nsmnow-admin-scripts - 20120724-0ubuntu0securityonion156 now available for Security Onion!

The following package is now available:
securityonion-nsmnow-admin-scripts - 20120724-0ubuntu0securityonion156

This package should resolve the following issue:

NSM: stderr redirects when listing logfiles #1086
https://github.com/Security-Onion-Solutions/security-onion/issues/1086

Thanks
Thanks to Pete Nelson for submitting the pull request and to the following for testing the new package:
Wes Lambert
Pete Nelson

Updating
These packages are now available in our stable repo.  Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
Need training?  Please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Security Onion Conference 2017 Registration is open!

Registration is now open for Security Onion Conference 2017!  For more details and to register, please see:
https://securityonion.net/conference

Wednesday, June 28, 2017

securityonion-sostat - 20120722-0ubuntu0securityonion71 now available for Security Onion!

The following package is now available:

securityonion-sostat - 20120722-0ubuntu0securityonion71

This new package should resolve the following issues:

sostat: netsniff-ng log section can get quite lengthy #1021
https://github.com/Security-Onion-Solutions/security-onion/issues/1021

sostat: check for stuck ELSA cron.pl #1061
https://github.com/Security-Onion-Solutions/security-onion/issues/1061

sostat: calculate netsniff-ng packet drops as percentage #1107
https://github.com/Security-Onion-Solutions/security-onion/issues/1107

These packages have been tested by the following (thanks!):
Wes Lambert
Rob Bardo

Updating
These packages are now available in our stable repo.  Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
Need training?  Please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Tuesday, June 27, 2017

PF_RING 6.6.0 and Suricata 3.2.2 now available for Security Onion!

The following software was recently released:

PF_RING 6.6.0:
http://www.ntop.org/pf_ring/pf_ring-6-6-just-released/

Suricata 3.2.2
https://suricata-ids.org/2017/06/07/suricata-3-2-2-available/

The following packages are now available:

securityonion-daq - 2.0.6-0ubuntu0securityonion7
securityonion-pfring-daq - 20121107-0ubuntu0securityonion14
securityonion-pfring-devel - 20121107-0ubuntu0securityonion11
securityonion-pfring-ld - 20120827-0ubuntu0securityonion11
securityonion-pfring-module - 20121107-0ubuntu0securityonion29
securityonion-pfring-userland - 20170619-1ubuntu1securityonion2
securityonion-suricata - 3.2.2-1ubuntu1securityonion1

These new packages should resolve the following issues:

Issue 1101: PF_RING 6.6.0
https://github.com/Security-Onion-Solutions/security-onion/issues/1101

Issue 1102: Suricata 3.2.2
https://github.com/Security-Onion-Solutions/security-onion/issues/1102

These packages have been tested by the following (thanks!):
Wes Lambert
Kevin Branch
Rob Bardo

Updating
These packages are now available in our stable repo.  Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
Need training?  Please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Thursday, June 15, 2017

Quick Intro to Security Onion Elastic Stack Technology Preview 2

Here's a video showing the installation of Security Onion Elastic Stack Technology Preview 2 and a brief introduction to the interface and workflow:
https://www.youtube.com/playlist?list=PLljFlTO9rB15SMpdBpLi084FiTBJsBjXZ

We'd love your feedback!  Please send it to our mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists

Thanks!

Tuesday, June 6, 2017

Search This Blog

Featured Post

Security Onion 3.3.0 Now Available including Agentic AI Improvements!

Security Onion 3.3.0 is now available and includes new features, updated components, and many quality of life improvements! For a full scree...

Popular Posts

Blog Archive