Build your Detection Lab with Security Onion

  Рет қаралды 30,827

Hack eXPlorer

Hack eXPlorer

4 жыл бұрын

Today, we’ll look at how we can build a Security Onion environment that will inspect the attack traffic between a Kali and Windows work station.
This set up is a simple design that incorporates minimum hardware requirements, and dose not require advanced networking setup.
Required Software
Security onion
securityonion.net/
Free Microsoft Windows 10 VM
developer.microsoft.com/en-us...
#CyberSecurity #ThreatHuning #SecurityOnion #SecurityLearning

Пікірлер: 63
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Hi, Please check the - FTP Attack and detection scenario using this LAB setup. Watch here : kzbin.info/www/bejne/inmxqYuFnL6ro80
@BFF-zb1qn
@BFF-zb1qn 2 ай бұрын
Awesome concept
@neonipun
@neonipun 4 жыл бұрын
Looking forward to the other parts! I was searching for security onion related resources and was pleasantly surprised to find this for an exact setup I'm trying to build! Awesome 👍
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Glad to be a help, Thankyou 👍
@Wasko2
@Wasko2 4 жыл бұрын
Was about to say the exact same thing :P
@shaunsolomon1496
@shaunsolomon1496 3 жыл бұрын
Awesome ! I am currently in the process of setting up a lab and wanted to learn about Security Onion. I am so glad to have found your video.
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Thankyou for the feed back, also try thr latest version of security onion 2.3, but it requires a lot of hardware.16 is good for a low power device
@hillfordh816
@hillfordh816 4 жыл бұрын
This was exactly what I was looking for, thanks man! I'm building this to test out some MITRE ATT&CK techniques
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Thanks Henry, glad it helped you..
@cyb3rmeerk4t51
@cyb3rmeerk4t51 4 жыл бұрын
I just had binged watched ALL of your videos. You really explain things well. Thank you very much for sharing us your knowledge. Hopefully we can see more of your security onion episodes and more of real life sample scenarios. I found out that your previous video was last year. Hopefully you can make your next video a little sooner and not on 2021 hehe. Thank you for creating such wonderful contents. I learn a lot from your videos. Keep safe.
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
HI Mandz, Glad you like them :D
@mongmongthunmarma4155
@mongmongthunmarma4155 4 жыл бұрын
Very clear concept, awesome! Thank you so much
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Thankyou for the feedback Mong
@seb1190
@seb1190 2 жыл бұрын
thank a lots for your great tuto!
@nitinmaurya6835
@nitinmaurya6835 3 жыл бұрын
Thanks Sir, I request you to keep please keep posting. I went through many youtube video tutorials but I could not understand where and how to set up interfaces. I was stuck in NAT and Host Only options and was not getting logs on Security Onion but your video helped me to correct everything. Please make keep making such videos.
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
I am glad it helped yoi nitin, this was my goal. And yes, i want to make more interesting amd informational videos like this in the future . Need the support of yoo guys 👍👍. Thanks
@siamshawkat3339
@siamshawkat3339 4 жыл бұрын
Awesome tutorial!!! Thanks sir.
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Thankyou Siam 👍
@zaneelali3237
@zaneelali3237 Жыл бұрын
Great video thanks
@shehzadarshad2000
@shehzadarshad2000 2 жыл бұрын
Hi Dud you did really good job i have made some good videos regarding the Security onion and Kali Linux penetration testing
@javedanwar1122
@javedanwar1122 4 жыл бұрын
This is good stuff to learn keep it up bro.....waiting for more parts.....Thanks
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Thank you for the feedback Javed
@gaderic
@gaderic 3 жыл бұрын
Thank ya
@rulofbaltwin3117
@rulofbaltwin3117 3 жыл бұрын
thanks bro this really helped me
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Thankyou for the feedback 👍
@muruga403
@muruga403 4 жыл бұрын
thanks
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
It's always a pleasure 👍
@oai9106
@oai9106 3 жыл бұрын
Thank you very much good explanation please try to do more about analyzing traffic with some sample malware file pcap using security onion Cheers Bro
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
As soon as possible OAI ,thank you
@alijasem2048
@alijasem2048 10 ай бұрын
can I use onion to minter other devices outside of MY NETWORK
@javedanwar1122
@javedanwar1122 4 жыл бұрын
Hi, how can we put our Nic to promiscuous mode or monitor mode if we install security onion to physical computer with two Nic let us know command way to do so.... Thanks
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
SO Will automatically do it for you, in a physical setup you need to send the network data to the sniffing interface via a span port or port mirroring www.blackhillsinfosec.com/webcast-how-to-build-a-home-lab/ Hope the above helps
@priyankaravi470
@priyankaravi470 4 жыл бұрын
hello! this video was very informative! can you run attacks on microservices? which are running using kubernetes and kibana? any ideas on how to do this?
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Yes we can, the path is to use ELK SIEM, you might need to create you own use cases, since this is new konghq.com/blog/10-ways-microservices-create-new-security-challenges/
@yagneshpatel2127
@yagneshpatel2127 3 жыл бұрын
Thanks for the easy method to setup. Unfortunately, I can not see anything in Sguil after login. Should I do any modification?
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Do you see the traffic flow coming I to the SO VM? you can use tcp dump. I hope all your VMs are in one network( as I did here all are in the( local host mode)
@aliasgarrassiwala9113
@aliasgarrassiwala9113 3 жыл бұрын
hey, the video was great. I have a question for you i can see the traffic by doing the TCPdump but when i am opening the squill i cant see the traffic can you please help me with this.
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Hi Aliasgar, first check if you can pin the VM with each other. Second you should have promiscuous mode enable on the sniffing interface in the SO host
@ishapathak8958
@ishapathak8958 4 жыл бұрын
Hey, Thanks for the video. It's really helpful though I have an issue-: when I run sudo so-status, it shows FAIL status for so-elasticsearch, so-logstash and so-kibana. Can you giude me through this? FYI- My VM settings for security onion are : 2GB memory, 50 GB hard disk storage and 2 processors.
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Hi Isha, the main problem is your ram, you need to allocate at least 8 gb of RAM for the VM.
@ishapathak8958
@ishapathak8958 4 жыл бұрын
@@HackeXPlorer I tried but it did not work. Now even, so-curator and so-elastalert shows FAIL status.
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Hi Isha, your HW requirements matches the minimum. usually elastic related issues occurs when low HW configurations. Even when I run at 8GB and 4 cores logstash takes some time to load (approx 10min). As a last resort can you increase the number of core's from 2 to 4. Let me know your progress.
@ishapathak8958
@ishapathak8958 3 жыл бұрын
Hack eXPlorer Hey, I tried reinstalling and setup from the scratch keeping my ram for vm as 4gb and 2 processors. It’s actually working completely fine now and all the services are up. I wonder what could’ve been the issue before. Thanks a lot for all your help.
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Wow, nice to hear that, stay tuned for more experiments from this setup 👍
@MrAnik001
@MrAnik001 4 жыл бұрын
Every time we wouldn't be able to setup Security Onion in same Network or Network segment. How would we monitor Network devices of other Network or vlan (With in a same Company )? Is their any way to monitor devices via SNMP or Netflow by Security Onion?
@HishanShouketh
@HishanShouketh 4 жыл бұрын
Hi Rahman , This video was intended for small home test lab setup, but you can do all you require above from SO. in security onion production mode you can install a security onion instance as a sensor only mode, which will will send information to the central security onion management server. you can place the sensors on server cluster ,DMZ or another install . securityonion.readthedocs.io/en/latest/post-installation.html Security onion is running ELASA which can phrase SNMP blog.securityonion.net/2019/12/security-onion-160463-now-available.html For net-flow www.reddit.com/r/securityonion/comments/an2tu4/netflow_ipflow_ipfix_support/
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Hop you got your answer
@siamshawkat3339
@siamshawkat3339 4 жыл бұрын
Looking for part 2 of this tutorial in more details and various attack analysis.
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Sure why not, I have planned some scenarios. What type of attacks are you interested in?
@siamshawkat3339
@siamshawkat3339 4 жыл бұрын
Sir, if possible i would like to watch demonstration on ip spoofing, dhcp snopping etc. Also detection and prevention mechanisms. Sir, do you have any social media account?
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
you can find me in FB, Twitter as HackExplorer
@dummyaccount8483
@dummyaccount8483 3 жыл бұрын
Hello. Can you make another video like this for the new SO 2.3 version? Can't get it working man haha I tried several times.
@dummyaccount8483
@dummyaccount8483 3 жыл бұрын
It's weird I surely followed everything in the website and the network adpater setup here in your video but my host could't still pull up the SO web from the SO VM. Thanks in advance.
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
@@dummyaccount8483 interesting can you access the webpage within the SO vm?
@dummyaccount8483
@dummyaccount8483 3 жыл бұрын
@@HackeXPlorer Got it working now man. I changed NAT to bridge. thanks!
@yagneshpatel2127
@yagneshpatel2127 3 жыл бұрын
I see this --> Warning: no preprocessors configured for policy 0
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Do you see the traffic flow coming I to the SO VM? you can use tcp dump. I hope all your VMs are in one network( as I did here all are in the( local host mode)
@Snu778
@Snu778 4 жыл бұрын
Plzz make video on how to monitor and detect ransomware on siem
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Sure
@HelloWorld435
@HelloWorld435 Жыл бұрын
This a good content and we need more like this and if you dont mind i need your linkdin or email in private.
@lorenzasodisen657
@lorenzasodisen657 3 жыл бұрын
I'm trying to install Security Onion in VMware but it requires me to have a 100GB storage as a minimum requirements. Is there any workaround on this? I just want to install it for studying purposes. Thanks
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Hi Lorenz, for security onion 2.0 you need 100GB at a minimum. here I have used SO16 for demo purpose.
@hillfordh816
@hillfordh816 3 жыл бұрын
I've learned the hard way....obey all of the resource requirements of Security Onion! It might seem like it installs fine but certain things won't work and you'll waste too much time troubleshooting. You might benefit from buying an old server to dedicate to SO.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
John Hammond
Рет қаралды 396 М.
SNORT Workshop : How to Install, Configure, and Create Rules
35:13
Hack eXPlorer
Рет қаралды 54 М.
УГАДАЙ ГДЕ ПРАВИЛЬНЫЙ ЦВЕТ?😱
00:14
МЯТНАЯ ФАНТА
Рет қаралды 4,3 МЛН
MISS CIRCLE STUDENTS BULLY ME!
00:12
Andreas Eskander
Рет қаралды 18 МЛН
EVOLUTION OF ICE CREAM 😱 #shorts
00:11
Savage Vlogs
Рет қаралды 7 МЛН
DEFINITELY NOT HAPPENING ON MY WATCH! 😒
00:12
Laro Benz
Рет қаралды 63 МЛН
Learn Tcpdump - Tutorial with Examples
15:02
Hack eXPlorer
Рет қаралды 8 М.
Cybersecurity Detection Lab: Installing Security Onion V2
22:02
How to know if your PC is hacked? Suspicious Network Activity 101
10:19
The PC Security Channel
Рет қаралды 1,2 МЛН
Bootstrap your Network Security Monitoring with Security Onion
10:54
Attack Detect Defend
Рет қаралды 11 М.
Detecting Suspicious Activity on Linux Endpoints Using Security Onion
51:36
How to use Volatility - Memory Analysis For Beginners.
25:25
Hack eXPlorer
Рет қаралды 26 М.
УГАДАЙ ГДЕ ПРАВИЛЬНЫЙ ЦВЕТ?😱
00:14
МЯТНАЯ ФАНТА
Рет қаралды 4,3 МЛН