No SecurityOnion videos yet. You could help us improve this page by suggesting one.
Based on our record, SecurityOnion seems to be a lot more popular than Ossec. While we know about 23 links to SecurityOnion, we've tracked only 1 mention of Ossec. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.
I'd take it one step further and install OSSEC as well. It can be configured to run as a local daemon and report suspicious activity, and also intervene. So if somebody is brute-forcing the login on your web page, it'll create a burst of 401s which OSSEC will detect in the logs and block the offender for X minutes/hours. Source: over 2 years ago
You’re looking for Security Onion, https://securityonionsolutions.com/. It’s a bunch of integrated tools that will sniff traffic and show alerts. Self hosted, open source, and free. Source: 5 months ago
Grab Security Onion for some blue team tools, try to get Zeek, Wazuh, and Suricata working and look at the output. Source: 10 months ago
If you want a GUI tool try Security Onion. (https://securityonionsolutions.com/). It is essentially zeek & more wrapped up in an easy to use GUI. Source: 10 months ago
Used security onion many years ago. https://securityonionsolutions.com/. Source: over 1 year ago
Active Measures - Includes (IDS/IPS) such as open-source Suricata or Snort on pfSense, and File Integrity Monitoring (FIM), such as the commercial Tripwire and dated, open-source Tripwire, or the open-source Wazuh installed on servers. These can be combined into a Security Information and Event Management (SIEM) system like the open-source solution, Security Onion. Wazuh itself has evolved into a SIEM. Source: over 1 year ago
snort - Snort is a free and open source network intrusion prevention system.
Suricata - Suricata is a high performance Network IDS, IPS and Network Security Monitoring engine.
McAfee Network Security Platform - McAfee Network Security Platform guards all your network-connected devices from zero-day and other attacks, with a cost-effective network intrusion prevention system.
Wazuh - Open Source Host and Endpoint Security
AIDE - AIDE (Advanced Intrusion Detection Environment) is a file and directory integrity checker.
AlienVault OSSIM - Alienvault integrates and correlates many popular network and security monitoring tools in one...