BRO/Zeek IDS content pack contains pipeline rules, a stream, a dashboard displaying interesting activity, and a syslog tcp input to capture and index BRO/Zeek logs coming from a remote sensor.
-
Updated
Apr 12, 2020
BRO/Zeek IDS content pack contains pipeline rules, a stream, a dashboard displaying interesting activity, and a syslog tcp input to capture and index BRO/Zeek logs coming from a remote sensor.
This project aims to enhance intrusion detection using Security Onion by integrating machine learning models for improved alert prioritization.
Code, labs and supporting materials for the book Industrial Cybersecurity, 2nd Edition
Collection of PatternDB files to parse Ubiquiti Unifi events into Security Onion's Syslog-NG and ELSA
Elasticsearch ingest pipeline for ASUS ROG router syslog in Security Onion 3.1
Evidence-backed SOC L1 portfolio: 100 detection and investigation scenarios across 16 MITRE ATT&CK categories — including false-positive triage, proactive threat hunting, and insider-threat analysis. From a segmented enterprise lab, entirely open-source.
Test your IDS with a simple python2.7 SCAPY tool.
YARA signature | YARA rule for Detecting Voldemort Malware
AstoraSOC is an open-source SOC and Incident Response platform for SIEM alert triage, case management, IOC intelligence, asset correlation, containment workflows, and professional reports
Security Onion Packet Capture Download scripts
Standalone Security Onion Setup + Network Simulation using Two Devices
Security Operations Center: pfSense firewall, Security Onion IDS/IPS, Splunk SIEM, Wazuh EDR and Microsoft Defender for Endpoint — multi-layered threat monitoring, detection and incident response
A Security Onion deployment project for intrusion detection and log analysis. Includes standalone, pfSense, internal, and cloud scenarios with Suricata, Zeek, Wazuh, and ELK stack integration.
Presenting a guide and systematic methodology for implementing securityonion / ELK elastic search stack. Checklists, Samples, Tips, and Tricks
Self-hosted LLM triage for Security Onion alerts
Full penetration test & SOC monitoring lab — Kali Linux, Metasploit, Security Onion 3.0
Security Onion
Security Onion SOC home lab using Kali Linux and Ubuntu to generate, detect and investigate network activity with Suricata, Alerts, Hunt and PCAP.
Hands-on cybersecurity home lab: Security Onion SIEM/IDS, Windows Server 2025, Active Directory, incident response, SOC analyst skills.
To associate your repository with the security-onion topic, visit your repo's landing page and select "manage topics."