@securityonion

Peel back the layers of your enterprise and make your adversaries cry! FREE and OPEN platform BY defenders FOR defenders!

Joined September 2012
Security Onion 3.3.0 is now available, including improvements to the new Agentic AI functionality, updated components, better Logstash tuning options, and more! Blog post with all of the details is in the comments. It's time to make some soup!
1
2
10
996
Security Onion Solutions is coming to GrrCON! Join us on Thursday and Friday at booth number 91 to learn how to peel back the layers of your network and make the adversaries cry. See you there!
1
3
451
HOTFIX released! We have released a hotfix to this week's 3.3.0 release to fix two issues: 1. An upstream change to an Elastic component requires x86_64-v3 CPU instruction set compatibility; this may cause issues if you have an older CPU or are using a Proxmox VM for your Security Onion node(s). 2. Disabling memory by default for the Onion AI Assistant. Full details are in the blog post linked in the comments.
1
1
3
827
Blog post with the full description of updates, changes, and improvements: blog.securityonion.net/2026/…
1
1
219
Good morning, Garden City! If you're at #AFCEATechnet Augusta this week, come see us at booth P11 and learn about using Security Onion to peel back the layers of your network and make the bad guys cry.
1
1
557
Registration is NOW OPEN for Augusta Cyber Week 2026, from October 19-24. This includes a four day instructor-led Security Onion training course, the twelfth annual Security Onion Conference, and wrapping up with @BSidesAugusta! See the link for more details. blog.securityonion.net/2026/…
2
1
5
832
One of the new features that we released in Security Onion 3.2 last week was Investigative Playbooks for the included Sigma detection rules. This means that alerts generated from log entries -- for example, a suspicious process execution event on an endpoint -- will now have Guided Analysis steps available for the analyst to follow, complete with live data pulled from your Security Onion logs. And as always, you can also write your own Playbooks as part of your detection engineering process, so the investigation and response workflow is tailored to your environment. You can view these playbooks in the Detections module in SOC, or see them all in our public GitHub repo.
4
1
7
1,386
ICYMI: New Security Onion release last week.
Security Onion 3.2.0 is NOW AVAILABLE, with a whole bunch of new features and quality of life improvements. - Initial implementation of Agentic AI functionality - Gemma now available as a hosted AI model - Datastream Lifecycle Management - ES|QL support for Sigma rules - Updates to nearly two dozen major components For a full description of all the new awesomeness, see our blog post: blog.securityonion.net/2026/…
2
3
1,002
Security Onion 3.2.0 is NOW AVAILABLE, with a whole bunch of new features and quality of life improvements. - Initial implementation of Agentic AI functionality - Gemma now available as a hosted AI model - Datastream Lifecycle Management - ES|QL support for Sigma rules - Updates to nearly two dozen major components For a full description of all the new awesomeness, see our blog post: blog.securityonion.net/2026/…
2
6
1
10
1,795
Excited to be sponsoring BSides Atlanta this year - looking forward to seeing everyone in October!
We’re excited to announce that @securityonion is supporting BSides Atlanta 2026 as a Silver sponsor! Huge thanks to the team at Security Onion Solutions for supporting the Atlanta security community. Check them out here: securityonion.com
1
5
1,227
We are once again hosting our annual user conference in beautiful Augusta, GA on October 23, and we want to hear from you! Our Call For Presenters (CFP) is open through this weekend, and we're looking for speakers with unique use cases, hunting techniques, integrations, or other examples of how to use Security Onion to secure a network. Come share your knowledge with your fellow blue teamers! securityonionsolutions.com/c…
2
5
634
HAPPY BIRTHDAY TO US! Today marks the twelfth birthday of Security Onion Solutions -- a dozen years of providing training, support, and other services on top of the free and open Security Onion platform. Here's to many more!
🤖 Made with AI
3
1
8
708
USING SOFTWARE RAID? We've identified an issue with an updated release of mdadm that could cause problems for Security Onion deployments using software RAID filesystems. If that applies to you, this blog post has more information: blog.securityonion.net/2026/…
1
2
913
Curious about the Human-Centered Investigative Playbook (HCIP) standard that underlies our Guided Analysis feature? If you're going to be at @BSidesPGH this week, come see our Senior Engineer Matthew Gracie, presenting in the afternoon on that very topic. Hope to see you there!
2
3
538
JUST POSTED: We've just released an update to our Introduction to Security Onion overview video, recorded with Security Onion 3. Learn all about the platform, how it fits into your security architecture, the ways to pivot between logs from your network and your endpoints, and how it's all wrapped up in a lovely new interface. Alert investigation, detection engineering, ad hoc threat hunting -- Security Onion has everything you need to peel back the layers of your network and make the bad guys cry. youtu.be/xKWn_YlVOGo
2
5
950
DID YOU KNOW? Security Onion Pro includes a feature called Manager of Managers, or MoM, which leverages the Security Onion API to allow access to other Security Onion installations in your environment from a central console. Perfect for MSSPs, for independent subsidiaries, for geographically siloed security teams, for dev environments, and more! Check out this video for more details. youtu.be/7CKPKkyu8pA
1
2
4
991
DID YOU KNOW? It's possible to enable or disable Suricata NIDS rules in Security Onion using regular expressions -- if you want to turn off all of those ET INFO or TOR alerts, this is an easy way to do it. And the best part is it will apply to new rules that are added to the set in the future. More information here: docs.securityonion.net/en/3/…
1
3
7
904
Security Onion retweeted
🚀Introducing SO-CRATES 1.0 — Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus! SO-CRATES is a single container image for analyzing pcap files, log files, and binary files. It was formerly known as OhMyPCAP. Here's what you can do with SO-CRATES: ✅analyze pcap files and then review Suricata alerts, metadata, and extracted files ✅import log files and then review Sigma alerts and the original log entries ✅import binary files and then review YARA matches and file metadata All of this runs in a single Docker/Podman container — perfect for air-gapped environments, malware analysis, incident response, threat hunting, forensics & teaching. Who’s trying it out? Drop a ❤️ and reply with your main use case! #DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma @Suricata_IDS @lennyzeltser @chrissanders88 @sansforensics @TomLawrenceTech
2
24
3
62
14,239
On this day in 2009 the very first release of Security Onion hit the Internet. A lot has changed since then, but it's still the best free and open solution to help you peel back the layers of your network and see what's really happening.
1
3
6
533