TOoSmOotH 

141 Followers
144 Following
99 Posts
VP of Products @ Security Onion Solutions LLC
Githubhttps://github.com/TOoSmOotH
@DavidJBianco @chrissanders88 Will there be BBQ involved?

#SecurityOnion 2.3.220 now available including:
#Elastic 8.6.2
#Grafana 9.2.10
#FleetDM 4.27.1
#Zeek 5.0.7
and more!

https://blog.securityonion.net/2023/02/security-onion-23220-now-available.html

Looking for a fun #CyberSecurity project? 😀

Want to practice your #ThreatHunting 🔍 and #IncidentResponse skills?

Install #SecurityOnion🧅2.3.220 in a VM:
https://docs.securityonion.net/en/2.3/first-time-users.html

Then follow along with our recent quick #malware analysis blog posts:
https://blog.securityonion.net/search/label/quick%20malware%20analysis

You can then stand up a production deployment and sniff live traffic from a tap or span port. You'll get NIDS alerts, protocol metadata, and full packet capture!
https://docs.securityonion.net/en/2.3/network.html

Then augment that network visibility with host visibility by deploying endpoint agents:
https://docs.securityonion.net/en/2.3/host.html

Once you find something of interest in your network or endpoint logs, you can escalate to a case:
https://docs.securityonion.net/en/2.3/cases.html

Inside the case, you can identify indicators and analyze them using Analyzers:
https://docs.securityonion.net/en/2.3/cases.html#analyzers

Looking for more documentation?

It's built into our web interface for #SecurityOnion 2.3.220 but you can also find it online at:
https://securityonion.net/docs

You can also purchase a printed copy of the documentation at https://securityonion.net/book with proceeds going to Rural Technology Fund!

The printed book also includes an inspiring foreword by @taosecurity and a 20% discount code for our certification and on-demand training!

Security Onion 2.3.220 now available including Elastic 8.6.2, Grafana 9.2.10, FleetDM 4.27.1, Zeek 5.0.7, and more!

Security Onion 2.3.220 is now available! It includes Elastic 8.6.2, Grafana 9.2.10, FleetDM 4.27.1, Zeek 5.0.7, and more: https://docs.secur...

I don't understand the educational value of giving a 7th grader 3 hours of homework.
Security Onion in 2022 and 2023

Here's a quick review of some of the major improvements we made to Security Onion 2.3 in the past year! Security Onion 2.3.100 added SOC Cas...

Been away from the socials mostly because I was switching daily drivers. Rocking a surface pro 8 and WSL2 with ubuntu and i3. Once I got past the systemd stuff its working great. I tried using straight up Ubuntu but a lot of the support is still sketch. I wanted to be able to draw and stuff like that. So far its working pretty good.
Introduction to Analyzers in #SecurityOnion: Enriching Observable Data in Cases During an Investigation
https://youtu.be/99LXr7UmtKI
Introduction to Analyzers in Security Onion

YouTube
Potential Security Issue in Windows Wazuh agent 3.13

This is a notification of a potential security issue in the Wazuh Windows agent. If you do not use Wazuh, then you can disregard this notifi...

Security Onion Documentation printed book now updated for #SecurityOnion 2.3.190!

https://blog.securityonion.net/2022/12/security-onion-documentation-printed.html

Security Onion Documentation printed book now updated for Security Onion 2.3.190!

Many folks have asked for a printed version of our official online documentation and we're excited to provide that!  Whether you work on ai...

@redteamwrangler I said DART gun!

#SecurityOnion 2.3.190 Hotfix Now Available!

This hotfix improves support for #Suricata file extraction into #Strelka:
https://blog.securityonion.net/2022/12/security-onion-23190-hotfix-20221207.html

Security Onion 2.3.190 Hotfix 20221207 Now Available!

We recently released Security Onion 2.3.190: https://blog.securityonion.net/2022/12/security-onion-23190-now-available.html Today, we are re...