Security Onion Lab: How to Install/Configure/Troubleshoot *NEW*

  Рет қаралды 80,294

Jesse K

Jesse K

5 жыл бұрын

The following is the link to my NEW course with coupon applied - Hands-on Penetration Testing Labs 3.0:
www.udemy.com/hands-on-penetr...
www.udemy.com/hands-on-penetr...
Here's my other courses with coupons applied if interested:
www.udemy.com/kali-linux-hand...
www.udemy.com/kali-linux-web-...
www.udemy.com/network-securit...
www.udemy.com/snort-intrusion...
Commands:
sudo reboot
cd Desktop
gedit terminal.desktop
[Desktop Entry]
Name=Terminal
Exec=/usr/bin/x-terminal-emulator
Terminal=true
Type=Application
Icon=/usr/share/icons/gnome/48x48/apps/gnome-terminal.png
sudo chmod +x terminal.desktop
sudo soup
sudo sostat | less
sudo nsm_sensor_ps-restart
locate zeus
sudo tcpreplay -l 20 -i enp0s8 -t /opt/samples/zeus-sample-1.pcap
URLs:
virtualbox.org
securitonion.net

Пікірлер: 100
@kwesikemet4829
@kwesikemet4829 5 жыл бұрын
You are one of the best ever teacher with such clarity that I have ever listen on utube! Millions thanks for this great share!
@JesseKurrus
@JesseKurrus 4 жыл бұрын
Thanks Kewsi, appreciated.
@metasploited5790
@metasploited5790 4 жыл бұрын
Thank you for your time and clear walkthrough :)
@stephannvibkronsk7690
@stephannvibkronsk7690 4 жыл бұрын
Great video. Pretty clear and useful. But, at the end of the process, I am not getting alerts on Squert, having run the exact same steps. Any help with this would be appreciated. Thanks!
@rewantmehta1
@rewantmehta1 4 жыл бұрын
Hi Jesse Thanks for this wonderful video. I have installed security onion and everything seems to be working fine. When we run the demo av file in it we can see the logs packets and all the relevant information. What do we have to do to use security only to capture live traffic via a spanned port and display traffic details on the kabana dashboard. We have tried everything and unfortunately we are unable to see any live traffic information. Or we can to capture file on a separate PC using wireshark and upload that .pcap ?
@jorgedelucas3650
@jorgedelucas3650 4 жыл бұрын
Best tutorial i seen so far!
@JesseKurrus
@JesseKurrus 4 жыл бұрын
Thanks Jorge.
@holyindian
@holyindian 5 жыл бұрын
Sir this is fantastic. You made me take my lab to the next level. I was wondering if you could make more videos for beginners like us to take us to the next level after installing the SO. More inclined towards advance setup, and how to monitor, analyze etc stuff. This will not only fill confidence in new users, but will also attract new enthusiasts to try out SO for their lab and enterprises.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Thanks @I am Root. Glad you found it helpful. Additional labs will be forthcoming. :)
@FranGrandees
@FranGrandees 4 жыл бұрын
Awesome, thanks Jesse!
@ranjithdoosa
@ranjithdoosa 3 жыл бұрын
Can you show how we can access Securityonion Console webpage, In latest version we have lot of ools included in SOC page
@kenatali9272
@kenatali9272 4 жыл бұрын
I will be trying it out tonight
@MarryJane2000
@MarryJane2000 4 жыл бұрын
great tutorial
@mohbra
@mohbra 4 жыл бұрын
Awesome tutorial I have subd
@ajaidx
@ajaidx 4 жыл бұрын
Can anybody tell how can i put my network interface to promiscuous mode in my vmware workstation pro15
@idogat3519
@idogat3519 4 жыл бұрын
i didn't understand how Security Onion communicate with the host. how data from the host flows to Security Onion - without sharing data from host how sguil for example can show alerts? (i'm new so sorry if the question is not clear enough)
@piagetblix
@piagetblix 3 жыл бұрын
Do you have anymore Videos on Security Onion? Is there an Udemy that focuses on Security Onion you teach?
@jillianstella
@jillianstella 5 жыл бұрын
I've followed every step, up to 'sudo tcpreplay -l 20 -i enp0s8 -t /opt/samples/zeus-sample-1.pcap ', however, Squert is not picking up on trojan alerts. Running on Hyper-V, advice is appreciated.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
@J, I believe we figured this out earlier. Used an upgrade command which messed up the OS. Only 'sudo soup' should be used to update Security Onion.
@rewantmehta1
@rewantmehta1 4 жыл бұрын
Hi Jesse Thankyou for this great video. Everything is working fine but I am not able to locate peek app using locate zeus and thus subsequent command is not running. How to resolve this?
@JesseKurrus
@JesseKurrus 4 жыл бұрын
Hmm, does the PCAP exist in the file system?
@carlosmoya8909
@carlosmoya8909 5 жыл бұрын
Hi Jesse, How are you doing? I really liked your video and full of great information and easy steps to follow. I did have some issues though and I would like some help solving them. I have tried to solve them I have not not had success yet. For instance, I had issues with seeing the quert alerts at the end and I think is because of the two issues. First issue is I couldn't set the network adapter from manual to automatic, once I press "apply" I receive an error" and the second issue is the "so-logstash" service keeps failing on me. I reset the services as you indicated in the video and this is the only service it keeps failing. I hope I could get some feedback and guidance, thank you in advance! Carlos Moya
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Carlos, completely reinstalling SO. Sounds like something went wrong with the installation.
@jasonh4329
@jasonh4329 4 жыл бұрын
Jesse. Good Stuff for noobs. Question about bridging my LAN interface on my laptop to make it the sniffing interface. I'm running VB 6.0 on my laptop (testing) per your setup instructions. Windows 10, Wifi interface connected to my LAN segment (just did NAT inside the VM), physical NIC on the laptop is not configured, but I have it in bridged mode connected to a SPAN of my internet WAN interface on my firewall. enp0s3 - mgmt nic enp0s8 - sniffer nic my win10 physical machine running Wireshark can see all traffic - promiscuously in the VM, tcpdump on the enp0s8 interface can only see broadcast and multicast, the VB settings for Adapter 2 is set to Bridged promiscuous mode - Allow ALL. I don't understand why VB/Ubuntu isn't seeing all traffic. help? also, will the SecOnion tools app see this traffic without additional configuration?
@JesseKurrus
@JesseKurrus 4 жыл бұрын
Jason, Try posting your question in the SO Google group - groups.google.com/forum/#!forum/security-onion
@gaganasri8450
@gaganasri8450 5 жыл бұрын
Unable to connect localhost on port 3374 . when I am starting sguil this error was occurring what I have to do?
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Have you tried restarting the sguil server? sudo nsm_server_ps-restart
@brycesnevadatrapline3712
@brycesnevadatrapline3712 4 жыл бұрын
When doing the locate zeus, and the 'sudo tcpreplay -l 20 -i enp0s8 -t /opt/samples/zeus-sample-1.pcap' , the trojan activity did not pop up in squert. after 20 minutes of troubleshooting, I was able to figure out that I didn't necessarily have enough RAM, and that the logstash wasn't working properly. I then tried the 'sudo sosetup-minimal' command, which seemingly fixed everything. Can you make any sense of this?
@brycesnevadatrapline3712
@brycesnevadatrapline3712 4 жыл бұрын
absolutely amazing video by the way!
@JesseKurrus
@JesseKurrus 4 жыл бұрын
Sounds like a coincidence to me.
@securityroute5254
@securityroute5254 5 жыл бұрын
I installed SO successfully, and update it, but nothing show on SGUIL, I checked all the services, all OK. I am running SO on VMware fusion (MAC). Any hint?
@JesseKurrus
@JesseKurrus 5 жыл бұрын
@Security Route, did you run the PCAP through tcpreplay using the correct sniffing interface? Did you try all troubleshooting steps outlined in this video? If so, I'd suggest you wipe out your Security Onion VM and reinstall it, following this video very carefully to rule out any mistakes in your setup. I haven't tested it on VMware Fusion personally. You can use VirtualBox on OS X, so you may want to try using that if you're following my guide.
@iIovegames
@iIovegames 5 жыл бұрын
Good video, thank you!
@iIovegames
@iIovegames 5 жыл бұрын
Not to my self: Security Onion needs 8 GB of memory. Otherwise Logstash cannot run properly.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
You're welcome @ilovegames.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
@ilovegames, it's recommended that you have at least 16 GB dedicated to SO.
@user-wp2hr1bk1p
@user-wp2hr1bk1p 4 жыл бұрын
so nice, very kind! thanks ^____^
@4cupsx01
@4cupsx01 4 жыл бұрын
Very clear instructions thank you. What would you do if you have no domain name? Can't get past this part of the install.
@JesseKurrus
@JesseKurrus 4 жыл бұрын
Np. Not sure what you mean. No domain name for what?
@4cupsx01
@4cupsx01 4 жыл бұрын
@@JesseKurrus on your demo you selected Dhcp during for IP assignment on enps03 but I chose static and inputed the IP info. The next requirement was to enter a domain name.
@JesseKurrus
@JesseKurrus 4 жыл бұрын
Any reason you can't choose DHCP? If you're not sure what to put for domain, you probably are safe to skip that part. It's only for if you have DNS set up I believe.
@4cupsx01
@4cupsx01 4 жыл бұрын
@@JesseKurrus the setup won't allow me to skip. My theory against Dhcp was every the system I might assign a new IP. For setting an interface for monitoring doesn't it need to have a static IP ?
@niteshthakur2237
@niteshthakur2237 4 жыл бұрын
Hi Jesse, Recently i have started my project under which i am configuring SO on AWS to monitor mirror traffic. But unfortunately i am also facing Below issues. >Internet is not working post installation: I am using Ubuntu 16.04, t2.large instance there are 2 interfaces on the instance eth0 and eth1 with no wireless interface. >Somehow elastic stack is also in failed state after installation. During installation i haven't encountered any issues or error which may result in elastic stack failure. I tried restarting ELK stack but it's not working. >AWS mirror events are reaching SO and i am able to see events through tshark on monitoring interface 1(eth1) Not able attach SS for your reference hence pasting output of /etc/network/interfaces and service status for your reference. Need your support to mitigate these issues. **************************************************************************************************** /etc/network/interfaces root@ip-10-1-2-84:~# cat /etc/network/interfaces # This configuration was created by the Security Onion setup script. # # The original network interface configuration file was backed up to: # /etc/network/interfaces.bak. # # This file describes the network interfaces available on your system # and how to activate them. For more information, see interfaces(5). # loopback network interface auto lo iface lo inet loopback # Management network interface auto eth0 iface eth0 inet static address 10.1.2.84 gateway 10.1.2.1 netmask 255.255.255.0 dns-nameservers 10.1.2.84 dns-domain lab.com auto eth1 iface eth1 inet manual up ip link set $IFACE promisc on arp off up down ip link set $IFACE promisc off down post-up for i in rx tx sg tso ufo gso gro lro; do ethtool -K $IFACE $i off; done post-up echo 1 > /proc/sys/net/ipv6/conf/$IFACE/disable_ipv6 # You probably don't need to enable or edit the following setting, # but it is included for completeness. # Note that increasing beyond the default may result in inconsistent traffic: # taosecurity.blogspot.com/2019/04/troubleshooting-nsm-virtualization.html # post-up ethtool -G $IFACE rx ********************************************************************************************************** SO service outcome root@ip-10-1-2-84:~# sudo so-status sudo: unable to resolve host ip-10-1-2-84: Connection refused Status: securityonion * sguil server [ OK ] Status: HIDS * ossec_agent (sguil) [ OK ] Status: Bro Name Type Host Status Pid Started bro standalone localhost running 6901 19 Sep 12:41:39 Status: ip-10-1-2-84-eth1 * netsniff-ng (full packet data) [ OK ] * pcap_agent (sguil) [ OK ] * snort_agent-1 (sguil) [ OK ] * snort-1 (alert data) [ OK ] * barnyard2-1 (spooler, unified2 format) [ OK ] Status: Elastic stack * so-elasticsearch/usr/sbin/so-elasticsearch-status: line 22: docker: command not found [ FAIL ] * so-logstash/usr/sbin/so-logstash-status: line 25: docker: command not found [ FAIL ] * so-kibana/usr/sbin/so-kibana-status: line 22: docker: command not found [ FAIL ] * so-freqserver/usr/sbin/so-freqserver-status: line 22: docker: command not fo und [ FAIL ] * so-curator/usr/sbin/so-curator-status: line 22: docker: command not found [ FAIL ] * so-elastalert/usr/sbin/so-elastalert-status: line 22: docker: command not fo und [ FAIL ] ************************************************************************************************************************* Thanks in Advance, Nitesh
@JesseKurrus
@JesseKurrus 4 жыл бұрын
Hey Nitesh. I've never installed it manually over Ubuntu so unfortunately I have no idea. You can try your question in the SO Google group - groups.google.com/forum/#!forum/security-onion
@tuyenpham7118
@tuyenpham7118 5 жыл бұрын
hello, i'm researching through security onion, i see SO apply the alert in download.conf, Can i create the alert in local.conf and use it ? and Can i ignore the alerts in the download.conf? thanks
@JesseKurrus
@JesseKurrus 5 жыл бұрын
@Tuyen Pham, what I think you're asking is if you can disable all the rules in downloaded.rules and only use the ones in local.rules. There's a few options to disable rules by sid, category, etc. You can disable all sids in downloaded.rules (using a PCRE), leaving only the sids in local.rules enabled. You could also disable all categories and not include any categories in local.rules, or make a new category which pertains to your local.rules and only leave that enabled. Check the following link for further details. github.com/Security-Onion-Solutions/security-onion/wiki/ManagingAlerts
@tuan23-nguyen96
@tuan23-nguyen96 5 жыл бұрын
@@JesseKurrus nice comment! Thank you sir.
@postdaddy1236
@postdaddy1236 3 жыл бұрын
How can we import syslog and AV logs in the security onion. Is there a way to import these files without connecting devices? Jesse K
@JesseKurrus
@JesseKurrus 3 жыл бұрын
Without connecting devices, I'm not sure. Check out the forums in the Security Onion Google group, they can give you an official answer - groups.google.com/g/security-onion?pli=1
@ringsticker5201
@ringsticker5201 5 жыл бұрын
how do i configure elastalert to send emails in security onion ?
@JesseKurrus
@JesseKurrus 5 жыл бұрын
@ring Sticker, check this resource - github.com/Security-Onion-Solutions/security-onion/wiki/ElastAlert
@steveleeminhui1982
@steveleeminhui1982 5 жыл бұрын
hi. how do i block ftp 21 and smtp 25 using SO?
@JesseKurrus
@JesseKurrus 5 жыл бұрын
If you mean incoming traffic to SO, it's already blocked by default with iptables. If you're referring to blocking the ports on the network, SO is a passive network security monitoring tool, not an IPS or a firewall.
@ashwinkumarkandasamy5011
@ashwinkumarkandasamy5011 5 жыл бұрын
excellent Video!!!!!!!!!!!! sir now i am started as noob in security monitoring now i want to know how security onion monitor other machines in the network?? is it all other machines in my network need any packages to install?? and how can i make my security onion monitor all my systems in the network.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
@Ashwinkumar Kandasamy, glad you liked it. If you followed this tutorial, it'll only monitor what's in your Local Area Network (LAN) in your host-only virtual network. If you want to monitor everything, you'll need a more advanced setup with real hardware (core switch, physical Security Onion server, etc.).
@ashwinkumarkandasamy5011
@ashwinkumarkandasamy5011 5 жыл бұрын
@@JesseKurrus thanks for the reply but I want to know it can discover automatically all machines in my LAN or we need do some setup in all machines.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Yes, add a virtual machine in the LAN that SO is monitoring and test it.
@cassiebarker718
@cassiebarker718 4 жыл бұрын
we did everything step by step till time frame of 7:18 minutes. and im getting Fatal : no bootable medium found. can you help with this?
@JesseKurrus
@JesseKurrus 4 жыл бұрын
askubuntu.com/questions/413594/what-does-no-bootable-medium-found-mean-in-virtualbox
@babitarimal7693
@babitarimal7693 4 жыл бұрын
Plz help. Cant use wireshark and network miner in sguil.
@JesseKurrus
@JesseKurrus 4 жыл бұрын
@Babita Rimal, you sure there's a PCAP associated with the alert? I'd have to know details like what error you're seeing (if any) when attempting to view the PCAP with Wireshark/Network Miner from sguil/squert.
@BananasAreG00d
@BananasAreG00d 5 жыл бұрын
Hi, I recently instaled SO, and everything seems to work, except when I try to run curl testmyids.com, I don't get any alerts, I checked if the rule is enabled and it seems to be, so I don't know what could be the problem. I'm totally new to all of this and would appreciate any suggestions
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Did you try all the troubleshooting steps outlined in this video? Restart sensor, reboot system, check sostat, etc.
@BananasAreG00d
@BananasAreG00d 5 жыл бұрын
@@JesseKurrus yes I did, and the tcpreplay also works and generates alerts, but testmyids doesn't do anything, also I get no alerts while doing anything online. Is there some speciffic way I need to generate traffic?
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Well if you followed the steps outlined in the video, the sniffing interface is host-only, which would not monitor any traffic via the NAT'd interface utilized to access public-facing websites (e.g. tedsmyids.com). Try replaying one of the malicious sample PCAPs in Security Onion with tcpreplay like I showed at the end of the video.
@BananasAreG00d
@BananasAreG00d 5 жыл бұрын
@@JesseKurrus yes I did and like I said that works perfectly, however I would like to utilize SO to monitor my home network. Do I need to install the production mode, or can I do something like port mirroring on this curent setup that you described in your video, so that I can monitor traffic happening when I visit various sites? If you could help with this or point me in a right direction I would be very grateful. Also I don't know if this is a stupid question or not but is it a problem if I'm using only WiFi connection, does SO work fine with that or does it striclty need to be ethernet connection?
@JesseKurrus
@JesseKurrus 5 жыл бұрын
So, as far as I know, it needs to be wired. For a home network monitoring setup you can use a switch that has port mirroring or a network tap that'll get all traffic fed to it, and plug in a dedicated SO box. Personally I just have experience installing, configuring, and monitoring it on other people's already existing network infrastructures. You can get a plethora of resources in the SO Google group here if you have any specific questions related to SO setups - groups.google.com/forum/#!forum/security-onion
@haseeburrehman7981
@haseeburrehman7981 5 жыл бұрын
can i install SO on centOS 7 ?
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Security Onion is only compatible with Ubuntu.
@jadecox4956
@jadecox4956 5 жыл бұрын
I know this may be tedious, but if possible, can you make a video on how to set up Security Onion with Proxmox? i.e. Mirroring traffic from a switch to a VM on Proxmox?
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Hey Jade. Never used Proxmox before, but it doesn't appear to be a feasible idea to me. Security Onion works best on real hardware in live environments. Although it may be possible to set up successfully, I've heard there's issues when using SO over virtualization. Why are you trying to mirror switch traffic on Proxmox exactly?
@jadecox4956
@jadecox4956 5 жыл бұрын
@@JesseKurrus thanks for the quick reply. I'm just trying to monitor network traffic on my home network for practice. I have an IBM server with promox installed that was given to me, along with a Tp-link switch. I'm planning on installing SO on the server using Proxmox and mirroring traffic from my switch to the SO vm. I've seen a few documentations about using openvswitch, but not 100% sure of the method. I know it's probably easier just to install SO on the server without virtualization, but I did not want to erase Proxmox from the server just yet.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Np. That makes sense. There's nothing wrong with doing it for practice, but I think it would be more relevant training to set it up on actual hardware and sniff the SPAN port or get a network tap for the switch and do it that way.
@jadecox4956
@jadecox4956 5 жыл бұрын
@@JesseKurrus So I was able to set up SO on Proxmox, and I found a way to mirror traffic from my network to the VM. I tested everything and it works fine (i.e. testmyids and the tcpreplay worked; however the events only showed in squert but not sguil). Any reason why this may be happening? I'm getting all "Ok"s sudo nsm_sensor_ps-restart as well. It's just strange to me that I'm seeing the alert in Squert but nothing in Sguil. Sguil is just empty.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Hey Jade. So, Squert pulls alerts from the sguil database, so if one works the other should also. I'm assuming you already tried rebooting. I'd need more information to adequately troubleshoot your problem. Do me a favor and post your issue and the results from "sudo sostat" command to the following Google group so that me and the Security Onion community can assist you better: groups.google.com/forum/#!forum/security-onion
@Upriva
@Upriva 4 жыл бұрын
Great tutorial. Followed every step, installed and verified smoothly. Still, I cannot log in to any tool. For instance when I log to sguil, it says invalid user name or pass. And I am inputting correct one. I did restart server, everything is OK, but still cannot log in. Anyone has same issue?
@JesseKurrus
@JesseKurrus 4 жыл бұрын
@Upriva, your user/pass should be what you selected in the Security Onion setup wizard. Either re-run setup or create a new sguil user - sudo nsm_server_user-add
@andrewoborn4732
@andrewoborn4732 5 жыл бұрын
I've got a noob question. At the end of the tutorial when opening Squert, I get a privacy error NET::ERR_CERT_AUTHORITY_INVALID. Should I worry about this? I didn't see it in your video. Any tips?
@JesseKurrus
@JesseKurrus 5 жыл бұрын
@Andrew Oborn, self signed certificate. Non issue.
@baohoang3769
@baohoang3769 5 жыл бұрын
@@JesseKurrus When I have the above problem, what should I do to be able to connect>
@JesseKurrus
@JesseKurrus 5 жыл бұрын
@bao hoang, click advances and proceed to page.
@darkspace5762
@darkspace5762 5 жыл бұрын
I found myself having to baby SO, if I just let it run for a while, something would break and some service would stop.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
Hey Darkspace, Sorry to hear that. You use Security Onion in production mode in a live environment? My experience has been pretty great by majority regarding Security Onion's performance and reliability.
@darkspace5762
@darkspace5762 5 жыл бұрын
@@JesseKurrus No, in a lab environment. Although I used production mode with all features enabled. I wouldn't want to deploy SO in a live environment. I like the idea of being able to do threat hunting with logstash and kibana but, unfortunately I do not view SO as reliable. That's my personal experience.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
​@@darkspace5762​ just curious, how much RAM and how many processors/cores do you have in your lab setup? If you don't have the proper hardware, SO isn't going to be reliable.
@jimducroiset1628
@jimducroiset1628 5 жыл бұрын
@@JesseKurrus Have used SO in both lab, single and distributed. Sometimes takes a little love to maintain but overall it's an absolutely awesome system to deploy in production.
@JesseKurrus
@JesseKurrus 5 жыл бұрын
@Jim Ducroiset, same here. SO rocks if you know what you're doing and have good enough hardware.
@zosmanovic9763
@zosmanovic9763 5 жыл бұрын
I installed this on my mums laptop
@instructormax7888
@instructormax7888 4 жыл бұрын
please who can help , i need to run command below , how to fix , thanks 1 max@max-VirtualBox:~$ sudo service nsm status ● nsm.service Loaded: not-found (Reason: No such file or directory) Active: inactive (dead) max@max-VirtualBox:~$
@JesseKurrus
@JesseKurrus 4 жыл бұрын
Try sudo so-status
Bootstrap your Network Security Monitoring with Security Onion
10:54
Attack Detect Defend
Рет қаралды 11 М.
you need this FREE CyberSecurity tool
32:06
NetworkChuck
Рет қаралды 1,2 МЛН
Пранк пошел не по плану…🥲
00:59
Саша Квашеная
Рет қаралды 6 МЛН
Strange File in Downloads Folder? Gootloader Malware Analysis
30:20
John Hammond
Рет қаралды 694 М.
Remotely Control Any Phone and PC with this Free tool!
17:15
Loi Liang Yang
Рет қаралды 822 М.
The BEST $800 Gaming PC Build of 2024!
18:29
TechSource
Рет қаралды 147 М.
Installing Security Onion
20:11
Cyber Warrior Studios
Рет қаралды 30 М.
Build your Detection Lab with Security Onion
21:44
Hack eXPlorer
Рет қаралды 30 М.
Metasploitable 3 Lab: Setup, Enumeration, and Exploitation
16:04
Detect Hackers & Malware on your Computer (literally for free)
16:38
Intrusion Detection System Tutorial: Setup Security Onion 2019
11:31
Sqearl Salazar
Рет қаралды 13 М.
НОВЫЕ ФЕЙК iPHONE 🤯 #iphone
0:37
ALSER kz
Рет қаралды 322 М.
Опасность фирменной зарядки Apple
0:57
SuperCrastan
Рет қаралды 10 МЛН
НЕ БЕРУ APPLE VISION PRO!
0:37
ТЕСЛЕР
Рет қаралды 371 М.