# Security Onion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

Repository: https://github.com/Security-Onion-Solutions/securityonion
Canonical: https://ross.abutalabs.com/products/security-onion
Homepage: https://securityonion.net
Language: Shell
License: NOASSERTION
License Family: other
Topics: case-management, cyber-security, endpoint-security, information-security, intrusion-detection-system, monitoring, network-security, security, security-tools, threat-hunting
Last push: 2026-08-26T20:52:59+00:00
Link (homepage): https://securityonion.net
Link (site_page): https://securityonionsolutions.com/pro

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 83, longevity 100
- inputs: {"age_days": 3131, "days_push": 7, "days_rel": 35, "gap_med": 34.0, "n_releases_24m": 23}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4846, forks 670 (observed 2026-08-28T04:09:01.341076+00:00)

## What it is
Security Onion is a free and open Linux distribution and platform for threat hunting, enterprise security monitoring, and log management. It bundles a unified web console (SOC) with Suricata, Zeek, the Elastic Stack, full packet capture, detections, and case management.

## Use cases
- monitor enterprise network security events
- hunt threats with full packet capture and Zeek metadata
- run network intrusion detection with Suricata
- centralize and search security logs
- manage alert triage and investigations with case management
- set up a self-hosted SOC on Linux

## When to choose
- you need an all-in-one, self-hosted network security monitoring and IDS platform
- you want Suricata, Zeek, and the Elastic Stack pre-integrated and maintained for you
- you need packet capture, alerting, dashboards, and case management in one console
- you are a SOC, government, or enterprise team doing threat hunting

## When to avoid
- you only need a lightweight host-based antivirus or endpoint agent
- you want a fully managed cloud SIEM with no infrastructure to run
- you cannot dedicate the substantial hardware resources Security Onion requires
- you need a simple log shipper rather than a full monitoring distribution

## Facets
- artifact type: application
- maturity: stable
- function: monitoring, search-engine, logging, security, alerting, analytics
- domain: security, networking, monitoring, self-hosted, developer-tools
- platform: self-hosted, cloud
- tags: threat-hunting, intrusion-detection, network-security-monitoring, suricata, zeek, elastic-stack, pcap, case-management, siem, log-management, linux, docker, web-server

## Member repositories
- Security-Onion-Solutions/securityonion (main) score 94
- Security-Onion-Solutions/security-onion (mirror) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:01.341076+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:18:26.563111+00:00, confidence not recorded.
  - readme: https://github.com/Security-Onion-Solutions/securityonion (fetched 2026-08-28T04:09:01.341076+00:00, sha aa4d3e144dd5)
  - homepage: https://securityonion.net (fetched 2026-08-29T09:01:22.042562+00:00, sha f4940a18affe)
  - site_page: https://securityonionsolutions.com/pro (fetched 2026-08-29T09:01:22.051776+00:00, sha 738a431b1f51)
- Data as of 2026-08-30T08:39:29.467469+00:00.
