Security Onion=$(cat SO.txt)A full enterprise SOC โ Suricata + Zeek + Elastic + dashboards โ in one free distro. Installing it turns your home lab into a mini operations center and your resume into evidence.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Give it disk & RAM; NSM stacks are hungry.
Pro tip: it passively watches โ no inline risk.
Zeek condenses packets into tidy protocols logs.
One click pivots from alert to packets โ explain this in interviews.
You just ran a SOC investigation solo. Screenshot it.
| soup | update platform |
| so-status | service health |
| Zeek logs | conn/dns/http/ssl |
| Alerts | Suricata + Sigma |
| Cases | incident tracking |
| pcap pivot | full evidence |
Boss of the SOC workflow maps cleanly onto this stack.
Sysmon logs can flow in via Elastic agents โ Windows visibility included.
Imperfect RAM? Wazuh first, Security Onion when you upgrade.
Screenshot dashboards + write one blog post: 'I built a SOC at home'.
Use Security Onion only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.