home/toolvault/security operating systems/security-onion

Security Onion //

Security Operating Systemsdefensefree / open

Security Onion=$(cat SO.txt)A full enterprise SOC โ€” Suricata + Zeek + Elastic + dashboards โ€” in one free distro. Installing it turns your home lab into a mini operations center and your resume into evidence.

difficulty ยท intermediate
60 min
time to first win
5
guided steps
0
students started here*

HOW TO USE SECURITY ONION

Follow the steps โ€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

security-onion โ€” guided lab session
static view
step 01

Install in a beefy VM

8โ€“12GB RAM, 2 vCPU+, evaluation mode

Give it disk & RAM; NSM stacks are hungry.

step 02

Feed it traffic

route lab traffic via its sniffing interface

Pro tip: it passively watches โ€” no inline risk.

step 03

Read what it saw

Dashboards โ†’ connections / dns / http

Zeek condenses packets into tidy protocols logs.

step 04

Hunt an alert

Alerts view โ†’ 'ET SCAN' from your nmapโ€ฆ

One click pivots from alert to packets โ€” explain this in interviews.

step 05

Case it up

Cases โ†’ create โ†’ attach observables

You just ran a SOC investigation solo. Screenshot it.

THE WORKFLOW AT A GLANCE

๐Ÿง…
Install
eval mode VM
๐Ÿ“ก
Monitor
lab traffic in
๐Ÿ“š
Logs
Zeek protocols
๐Ÿšจ
Alerts
Suricata/Sigma
๐Ÿ•ต๏ธ
Case
investigate
LEARNING CURVE
intermediate โ€” 60 min to first win

FLAGS & SUPER-MOVES

soupupdate platform
so-statusservice health
Zeek logsconn/dns/http/ssl
AlertsSuricata + Sigma
Casesincident tracking
pcap pivotfull evidence

PRO TIPS

01

Boss of the SOC workflow maps cleanly onto this stack.

Boss of the SOC workflow maps cleanly onto this stack.

02

Sysmon logs can flow in via Elastic agents โ€” Windows visibility included.

Sysmon logs can flow in via Elastic agents โ€” Windows visibility included.

03

Imperfect RAM? Wazuh first, Security Onion when you upgrade.

Imperfect RAM? Wazuh first, Security Onion when you upgrade.

04

Screenshot dashboards + write one blog post

Screenshot dashboards + write one blog post: 'I built a SOC at home'.

โš–๏ธ

Golden rule

Use Security Onion only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
โœ๏ธ Author LDM ยท ldmhub4u@gmail.com
full guide v1 ยท v2 immersive ยท latest news
Made for learners, everywhere ยท 2026
*plausibly. verify commands with official docs.