BRO/Zeek IDS content pack contains pipeline rules, a stream, a dashboard displaying interesting activity, and a syslog tcp input to capture and index BRO/Zeek logs coming from a remote sensor.
-
Updated
Apr 12, 2020
BRO/Zeek IDS content pack contains pipeline rules, a stream, a dashboard displaying interesting activity, and a syslog tcp input to capture and index BRO/Zeek logs coming from a remote sensor.
This project aims to enhance intrusion detection using Security Onion by integrating machine learning models for improved alert prioritization.
Collection of PatternDB files to parse Ubiquiti Unifi events into Security Onion's Syslog-NG and ELSA
Standalone Security Onion Setup + Network Simulation using Two Devices
YARA signature | YARA rule for Detecting Voldemort Malware
Test your IDS with a simple python2.7 SCAPY tool.
Security Onion Packet Capture Download scripts
Presenting a guide and systematic methodology for implementing securityonion / ELK elastic search stack. Checklists, Samples, Tips, and Tricks
A Security Onion deployment project for intrusion detection and log analysis. Includes standalone, pfSense, internal, and cloud scenarios with Suricata, Zeek, Wazuh, and ELK stack integration.
Security Operations Center: pfSense firewall, Security Onion IDS/IPS, Splunk SIEM, Wazuh EDR and Microsoft Defender for Endpoint — multi-layered threat monitoring, detection and incident response
Security Onion
Cybersecurity home lab — multi-VM environment (Windows, Linux, pfSense, Security Onion).
Full penetration test & SOC monitoring lab — Kali Linux, Metasploit, Security Onion 3.0
A fully segmented home SOC lab built on enterprise hardware with MikroTik networking, Proxmox virtualization, and a blue team tooling stack. Documented end to end.
Python-based port scan detection pipeline using Zeek logs
Full-spectrum cyber operation lab demonstrating red team exploitation and blue team detection using Security Onion SIEM, Metasploit, and MITRE ATT&CK.
Full-stack enterprise security lab - firewall segmentation, SIEM/EDR, AD, and attack simulation on a single host.
Security monitoring and log analysis — detection dashboards in Security Onion and Splunk.
Self-hosted NetBird VPN with Security Onion SIEM integration. Zero-trust mesh networking for secure cloud-local connectivity. 14.7M+ events monitored.
Add a description, image, and links to the security-onion topic page so that developers can more easily learn about it.
To associate your repository with the security-onion topic, visit your repo's landing page and select "manage topics."