@securityonioni
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Peel back the layers of your enterprise and make your adversaries cry! FREE and OPEN platform BY defenders FOR defenders!
Joined September 2012
- Tweets8.2K
- Following0
- Followers19.3K
- Likes4.7K
Pinned Tweet
Security Onion 3.3.0 is now available, including improvements to the new Agentic AI functionality, updated components, better Logstash tuning options, and more! Blog post with all of the details is in the comments.
It's time to make some soup!
Security Onion Solutions is coming to GrrCON!
Join us on Thursday and Friday at booth number 91 to learn how to peel back the layers of your network and make the adversaries cry. See you there!
HOTFIX released!
We have released a hotfix to this week's 3.3.0 release to fix two issues:
1. An upstream change to an Elastic component requires x86_64-v3 CPU instruction set compatibility; this may cause issues if you have an older CPU or are using a Proxmox VM for your Security Onion node(s).
2. Disabling memory by default for the Onion AI Assistant.
Full details are in the blog post linked in the comments.
Details available at our blog here:
blog.securityonion.net/2026/…
Blog post with the full description of updates, changes, and improvements:
blog.securityonion.net/2026/…
Good morning, Garden City! If you're at #AFCEATechnet Augusta this week, come see us at booth P11 and learn about using Security Onion to peel back the layers of your network and make the bad guys cry.
Registration is NOW OPEN for Augusta Cyber Week 2026, from October 19-24. This includes a four day instructor-led Security Onion training course, the twelfth annual Security Onion Conference, and wrapping up with @BSidesAugusta! See the link for more details.
blog.securityonion.net/2026/…
One of the new features that we released in Security Onion 3.2 last week was Investigative Playbooks for the included Sigma detection rules. This means that alerts generated from log entries -- for example, a suspicious process execution event on an endpoint -- will now have Guided Analysis steps available for the analyst to follow, complete with live data pulled from your Security Onion logs. And as always, you can also write your own Playbooks as part of your detection engineering process, so the investigation and response workflow is tailored to your environment.
You can view these playbooks in the Detections module in SOC, or see them all in our public GitHub repo.
ICYMI: New Security Onion release last week.
Security Onion 3.2.0 is NOW AVAILABLE, with a whole bunch of new features and quality of life improvements.
- Initial implementation of Agentic AI functionality
- Gemma now available as a hosted AI model
- Datastream Lifecycle Management
- ES|QL support for Sigma rules
- Updates to nearly two dozen major components
For a full description of all the new awesomeness, see our blog post:
blog.securityonion.net/2026/…
Security Onion 3.2.0 is NOW AVAILABLE, with a whole bunch of new features and quality of life improvements.
- Initial implementation of Agentic AI functionality
- Gemma now available as a hosted AI model
- Datastream Lifecycle Management
- ES|QL support for Sigma rules
- Updates to nearly two dozen major components
For a full description of all the new awesomeness, see our blog post:
blog.securityonion.net/2026/…
Excited to be sponsoring BSides Atlanta this year - looking forward to seeing everyone in October!
We’re excited to announce that @securityonion is supporting BSides Atlanta 2026 as a Silver sponsor!
Huge thanks to the team at Security Onion Solutions for supporting the Atlanta security community. Check them out here: securityonion.com
We are once again hosting our annual user conference in beautiful Augusta, GA on October 23, and we want to hear from you! Our Call For Presenters (CFP) is open through this weekend, and we're looking for speakers with unique use cases, hunting techniques, integrations, or other examples of how to use Security Onion to secure a network. Come share your knowledge with your fellow blue teamers!
securityonionsolutions.com/c…
HAPPY BIRTHDAY TO US!
Today marks the twelfth birthday of Security Onion Solutions -- a dozen years of providing training, support, and other services on top of the free and open Security Onion platform. Here's to many more!
🤖 Made with AI
USING SOFTWARE RAID?
We've identified an issue with an updated release of mdadm that could cause problems for Security Onion deployments using software RAID filesystems. If that applies to you, this blog post has more information:
blog.securityonion.net/2026/…
Curious about the Human-Centered Investigative Playbook (HCIP) standard that underlies our Guided Analysis feature? If you're going to be at @BSidesPGH this week, come see our Senior Engineer Matthew Gracie, presenting in the afternoon on that very topic. Hope to see you there!
JUST POSTED: We've just released an update to our Introduction to Security Onion overview video, recorded with Security Onion 3. Learn all about the platform, how it fits into your security architecture, the ways to pivot between logs from your network and your endpoints, and how it's all wrapped up in a lovely new interface. Alert investigation, detection engineering, ad hoc threat hunting -- Security Onion has everything you need to peel back the layers of your network and make the bad guys cry.
youtu.be/xKWn_YlVOGo
DID YOU KNOW? Security Onion Pro includes a feature called Manager of Managers, or MoM, which leverages the Security Onion API to allow access to other Security Onion installations in your environment from a central console.
Perfect for MSSPs, for independent subsidiaries, for geographically siloed security teams, for dev environments, and more! Check out this video for more details.
youtu.be/7CKPKkyu8pA
DID YOU KNOW?
It's possible to enable or disable Suricata NIDS rules in Security Onion using regular expressions -- if you want to turn off all of those ET INFO or TOR alerts, this is an easy way to do it. And the best part is it will apply to new rules that are added to the set in the future.
More information here: docs.securityonion.net/en/3/…
Security Onion retweeted
🚀Introducing SO-CRATES 1.0 — Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!
SO-CRATES is a single container image for analyzing pcap files, log files, and binary files. It was formerly known as OhMyPCAP.
Here's what you can do with SO-CRATES:
✅analyze pcap files and then review Suricata alerts, metadata, and extracted files
✅import log files and then review Sigma alerts and the original log entries
✅import binary files and then review YARA matches and file metadata
All of this runs in a single Docker/Podman container — perfect for air-gapped environments, malware analysis, incident response, threat hunting, forensics & teaching.
Who’s trying it out? Drop a ❤️ and reply with your main use case!
#DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma
@Suricata_IDS @lennyzeltser @chrissanders88 @sansforensics @TomLawrenceTech