Introduction to Security Onion 2.4
46:52
State of the Onion 2023
37:36
Жыл бұрын
Enrich Your Data and Your Life
25:02
What's New in Security Onion 2.4
5:17
State of the Onion
31:11
2 жыл бұрын
Security Onion Dashboards
15:35
2 жыл бұрын
Пікірлер
@SimplyAwesomeness
@SimplyAwesomeness Ай бұрын
Every homelab needs this.
@nico3006
@nico3006 Ай бұрын
is it okay if i install to a external SSD?
@security-onion
@security-onion Ай бұрын
You can try it, but we do not recommend or support it. If you have further questions or problems, please start a new discussion at securityonion.net/discuss
@and_still.
@and_still. Ай бұрын
Can you help me? I am not seeing any alert nor any data in any tools like kibana , etc... Iam trying to find out for more than 1 week.
@security-onion
@security-onion Ай бұрын
If you have questions or problems, please start a new discussion at securityonion.net/discuss and provide detailed information.
@waseemalkurdi759
@waseemalkurdi759 Ай бұрын
Thank you, It's very useful video.
@security-onion
@security-onion Ай бұрын
Thanks, glad you like it!
@swaterstsiafadray329
@swaterstsiafadray329 2 ай бұрын
Hi! how to do this with a Eval mode? Thank you!
@security-onion
@security-onion 2 ай бұрын
It should work the same for Eval mode. If you have further questions or problems, please start a new discussion at securityonion.net/discuss. Thanks!
@Dyosef95
@Dyosef95 3 ай бұрын
i try to install the nachine as shown in the video , in the end of the installation there is no way to access the web interface , i got the directory of the security onion on the machine but dont know what to do
@security-onion
@security-onion 3 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.com/discuss. Thanks!
@Sa-bk8cl
@Sa-bk8cl 23 сағат бұрын
I'm facing the same problem. Were you able to solve this problem?
@hariomojha2729
@hariomojha2729 3 ай бұрын
Hello sir , I am stuck at : 0curl: (6) Could not resolve host:sigs.securityonion.net , So can you please help me with this issue
@AngeliteEntyshak
@AngeliteEntyshak 3 ай бұрын
I am extremely excited to get my home lab set up. Thanks for the concise series, dude!
@security-onion
@security-onion 3 ай бұрын
Happy hunting!
@Bike1337
@Bike1337 3 ай бұрын
Excellent work
@TheSoliver84
@TheSoliver84 4 ай бұрын
Hello, now I ask again: in the evaluation version, are the results under Alert real or placeholders?
@security-onion
@security-onion 3 ай бұрын
The alerts are real. If you have further questions or problems, please start a new discussion at securityonion.com/discuss. Thanks!
@TheSoliver84
@TheSoliver84 4 ай бұрын
Are there real alarms in the evaluation or are the placeholders not real?
@security-onion
@security-onion 3 ай бұрын
The alerts are real. If you have further questions or problems, please start a new discussion at securityonion.com/discuss. Thanks!
@TheSoliver84
@TheSoliver84 3 ай бұрын
@@security-onion OK, how do I find the corresponding computers or devices? Only IP addresses are displayed but no MAC addresses.
@security-onion
@security-onion 3 ай бұрын
You may be able to find MAC addresses by pivoting to PCAP and then opening that PCAP in Wireshark or some other PCAP utility. However, depending on how you're monitoring traffic, the MAC addresses shown may not actually be the MAC addresses of the actual endpoints. For this reason, most folks focus on IP addresses rather than MAC addresses. Depending on your network, you may be able to correlate an IP address to an actual device via DNS, DHCP, or other means. If you have further questions or problems, plese start a new discussion at securityonion.com/discuss rather than replying here on KZbin. Thanks!
@ibejoe7719
@ibejoe7719 4 ай бұрын
My adversaries will grid their teeth after weeping....there's a need for a cert of completion to proof the understanding on how to peel the onion
@security-onion
@security-onion 3 ай бұрын
Thanks for watching Security Onion Essentials 2.3. Please keep in mind that Security Onion 2.3 has reached End Of Life and so we recommend watching Security Onion Essentials 2.4 for the latest and greatest. Regarding certificate of completion, we do offer that for our paid training classes at securityonion.com/training. We also offer the SOCP (Security Onion Certified Professional) at securityonion.com/certification.
@ibejoe7719
@ibejoe7719 4 ай бұрын
Good stuff....thanks for sharing
@security-onion
@security-onion 4 ай бұрын
Thanks for watching!
@L3af0553
@L3af0553 4 ай бұрын
I have watched the install videos and you installed the eval version, i plan on installing the desktop version and am wondering if i will still need to use the web interface to monitor traffic
@security-onion
@security-onion 4 ай бұрын
You will need some kind of web browser whether its inside the Security Onion Desktop or on some other machine. If you have further questions or problems, please start a new discussion at securityonion.net/discuss. Thanks!
@AbuFaizal
@AbuFaizal 4 ай бұрын
thanks for video
@security-onion
@security-onion 4 ай бұрын
You're welcome!
@callmebigpapa
@callmebigpapa 4 ай бұрын
Thank you so much this is great. You are a gifted teacher.
@security-onion
@security-onion 4 ай бұрын
Thanks for your kind words!
@WatsonInfosec
@WatsonInfosec 4 ай бұрын
Thanks
@security-onion
@security-onion 4 ай бұрын
You're welcome!
@fatushcorner
@fatushcorner 4 ай бұрын
Thank u ☺️
@security-onion
@security-onion 4 ай бұрын
You're welcome!
@edvloesungen
@edvloesungen 5 ай бұрын
Thank you very much!
@security-onion
@security-onion 5 ай бұрын
You're welcome!
@andreantunes7310
@andreantunes7310 6 ай бұрын
miss the suricata and logs of apps of pfsense, but great work, keep doing more, and integrations with flux
@fuzzyEuclid
@fuzzyEuclid 6 ай бұрын
An osquery video would be awesome :)
@CageYim
@CageYim 6 ай бұрын
I saw "Evaluation installs and Import installs do not support remote elastic agents. The links below are shown for demonstration purposes only." after I installed the eval version security onion following your installation guide video, is that means I have to install to other mode? Thank you.
@security-onion
@security-onion 6 ай бұрын
If you want to deploy the Elastic Agent to remote devices, then you will need to install in STANDALONE mode or do a full distributed deployment. For more information, please see the documentation at docs.securityonion.net/en/2.4/architecture.html. If you have further questions or problems, please start a new discussion at securityonion.com/discuss. Thanks!
@CageYim
@CageYim 6 ай бұрын
@@security-onion Thank you very much. Let me try again.
@flyingbyalexeiroudnev9750
@flyingbyalexeiroudnev9750 6 ай бұрын
I do not see a way to change severity by one click, or to suppress alert temporarily, or to automatically get IP etc from alert. So it looks as a good step but it is ONLY a FIRST STEP. For example,. we reclassify events in Zabbix all the time, we set up timed reclassifications often, we may need to update a GROUP of Detection rules at once. Idea is great but it looks as very first implementation yet. (Of course I can clone the rule, then change severity in the cloned rule and disable original rule. but why to do it so complicated? or we want to suppress all alerts 'traffic with ... group' whch we do by re: expression today - it's not implemented yet (looks this way) and there are 50+ IP groups and about 10 alerts per group... so what disable can do by single re: rule, detection will require 100 updates (looks like this).
@security-onion
@security-onion 6 ай бұрын
Yes, we have lots of improvements coming. If you have further comments or questions, please start a new discussion at securityonion.com/discuss.
@GarethLedger-pz6wl
@GarethLedger-pz6wl 6 ай бұрын
Any chance you paste the various command line inputs
@capitalreg318
@capitalreg318 7 ай бұрын
Oh this will be very useful. Cool feature indeed, thank you!! Two things: 1. Any possibility of adding an optional Elastic Defend/Predefined Rules integration to that Detections menu? Currently it is buried in Kibana and requires some additional digging to add the Predefined Rule integration, then unhide the Security tab Kibana Spaces? 2. Any chance of upgrading the OSquery Manager to the Velociraptor platform to integrate that amazing tool's DFIR capabilities with the SOC/Elastic Agent?
@security-onion
@security-onion 7 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.net/discuss
@zapphoddbubbahbrox5681
@zapphoddbubbahbrox5681 7 ай бұрын
somehow SYSMON integration not working or showing up as an integration for a windows box. i'd added SYSMON to the node after the agent was enrolled. does this require removal (big pains here also, it won't properly remove)? Would be great to have a guide for this. Also for Linux SYSMON
@security-onion
@security-onion 7 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.com/discuss
@Rabah_RAHLI
@Rabah_RAHLI 7 ай бұрын
can this functionality work with pfsense comunity edition ?
@security-onion
@security-onion 7 ай бұрын
Yes! If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@johnmosqueda1029
@johnmosqueda1029 7 ай бұрын
Is there an in place upgrade option available?
@security-onion
@security-onion 7 ай бұрын
There will be an in-place upgrade option once 2.4.70 is released. If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@juanmartinmerlo3682
@juanmartinmerlo3682 7 ай бұрын
I can't wait to upgrade! Is there an estimated release date? Great job team!
@security-onion
@security-onion 7 ай бұрын
2.4.70 is scheduled to release in the next few weeks. Stay tuned! If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@michaelporter8242
@michaelporter8242 7 ай бұрын
Wow, this is a great improvement for tuning. Can't wait to give it a try!
@security-onion
@security-onion 7 ай бұрын
Thanks, glad you like it!
@izid00d
@izid00d 7 ай бұрын
awesome, just as i imagined it in my head! i will look forward to the update, sheesh this will shorten the tuning process by a lot. Thanks to the SO Team!!!
@security-onion
@security-onion 7 ай бұрын
Thanks, glad you like it!
@TheLakeBodom
@TheLakeBodom 7 ай бұрын
Wow, nice works Security Onion Team!! This will be a much better work flow
@security-onion
@security-onion 7 ай бұрын
Thanks, glad you like it!
@cyberlabz
@cyberlabz 7 ай бұрын
I've watched the new video at least four times. Super excited about the Detections module release. Great job!!!!
@security-onion
@security-onion 7 ай бұрын
Thanks, glad you like it!
@frzen
@frzen 7 ай бұрын
Huge quality of life upgrade thank you I'm really looking forward to updating
@security-onion
@security-onion 7 ай бұрын
Thanks, glad you like it!
@Roman-m3u4h
@Roman-m3u4h 7 ай бұрын
Is it possible to revert changes through history? Is there a rule validator in the Signarutre field? Will the syntax color highlighting appear?
@security-onion
@security-onion 7 ай бұрын
If you have questions, please start a new discussion at securityonion.com/discuss
@yannickzelt9246
@yannickzelt9246 7 ай бұрын
This really is a great new feature. Can't wait to try it out.
@security-onion
@security-onion 7 ай бұрын
Thanks, glad you like it!
@ankuryogi3298
@ankuryogi3298 7 ай бұрын
Love it
@security-onion
@security-onion 7 ай бұрын
Thanks!
@jmcgee81
@jmcgee81 8 ай бұрын
Excellent keynote!
@security-onion
@security-onion 7 ай бұрын
Thanks for watching!
@giovannisvette449
@giovannisvette449 9 ай бұрын
Does this still work?
@security-onion
@security-onion 9 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.com/discuss
@sevadamuradyan5486
@sevadamuradyan5486 9 ай бұрын
our network firewall log is coming to my computer how can i send sec-onion?
@security-onion
@security-onion 9 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.net/discuss
@kinghenryjames1327
@kinghenryjames1327 9 ай бұрын
Awesome, great material great teacher.
@security-onion
@security-onion 9 ай бұрын
Thanks, glad you liked it!
@olivertatzmann3038
@olivertatzmann3038 9 ай бұрын
Thank you - Great tutorial. Unfortunately I failed to get it working neiger with pfSense nor with fortigate. tcpdump shows the incoming packages, but they are not parsed. Do you have any hint how to start toubleshooting?
@security-onion
@security-onion 9 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.com/discuss
@seckeymaker
@seckeymaker 9 ай бұрын
Hello, is Winlogbeat in 2.4.50 ?
@security-onion
@security-onion 9 ай бұрын
Winlogbeat has been replaced by Elastic Agent in 2.4. Documentation: docs.securityonion.net/en/2.4/elastic-agent.html#elastic-agent Video: kzbin.info/www/bejne/mXjQgoCpe9p0rNk If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@JamesHazell-b2p
@JamesHazell-b2p 9 ай бұрын
Great information. Is there a video to port Cisco switch log files to SO ?
@security-onion
@security-onion 9 ай бұрын
Please see the Cisco IOS integration at docs.elastic.co/integrations/cisco_ios and our docs at docs.securityonion.net/en/2.4/elastic-fleet.html#elastic-fleet and docs.securityonion.net/en/2.4/elastic-agent.html. If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@Angry.Hippie
@Angry.Hippie 9 ай бұрын
This video series has been a great help in getting me hands on experience for the CySA+ cert. Wouldn't of been able to install an agent on my computer without it!
@security-onion
@security-onion 9 ай бұрын
Thanks, glad to help!
@subhuman7478
@subhuman7478 9 ай бұрын
I would also love to see an osquery video. A strelka one would be great too.
@WatsonInfosec
@WatsonInfosec 10 ай бұрын
Thanks
@security-onion
@security-onion 9 ай бұрын
You're welcome!
@taraskobilskiy6538
@taraskobilskiy6538 10 ай бұрын
Thank you for the video
@security-onion
@security-onion 9 ай бұрын
You're welcome!
@GINACOMMISSO
@GINACOMMISSO 10 ай бұрын
Does the IP of the virtual machine (to access the SOC) has to be the same as that of the host computer?
@security-onion
@security-onion 9 ай бұрын
No, the VM and the host computer should have different IP addresses. If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@calmeidazim
@calmeidazim 10 ай бұрын
Thank you, just in the time :)
@security-onion
@security-onion 9 ай бұрын
You're welcome!