Security Onion
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek. observed · 2026-08-28
Health v2 · maintenance only
94/100
- Activity 99
- Release rhythm 83
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 34.0
- age_days: 3131
- days_rel: 35
- days_push: 7
- n_releases_24m: 23
Adoption not part of the score
4846 stars · 670 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Security Onion is a free and open Linux distribution and platform for threat hunting, enterprise security monitoring, and log management. It bundles a unified web console (SOC) with Suricata, Zeek, the Elastic Stack, full packet capture, detections, and case management.
Use cases
- monitor enterprise network security events
- hunt threats with full packet capture and Zeek metadata
- run network intrusion detection with Suricata
- centralize and search security logs
- manage alert triage and investigations with case management
- set up a self-hosted SOC on Linux
When to choose
- you need an all-in-one, self-hosted network security monitoring and IDS platform
- you want Suricata, Zeek, and the Elastic Stack pre-integrated and maintained for you
- you need packet capture, alerting, dashboards, and case management in one console
- you are a SOC, government, or enterprise team doing threat hunting
When to avoid
- you only need a lightweight host-based antivirus or endpoint agent
- you want a fully managed cloud SIEM with no infrastructure to run
- you cannot dedicate the substantial hardware resources Security Onion requires
- you need a simple log shipper rather than a full monitoring distribution
Facets
application · maturity stable
monitoring search-engine logging security alerting analytics security networking monitoring self-hosted developer-tools self-hosted cloud threat-hunting intrusion-detection network-security-monitoring suricata zeek elastic-stack pcap case-management siem log-management linux docker web-server
3 sources
- readme: https://github.com/Security-Onion-Solutions/securityonion · fetched 2026-08-28 · aa4d3e144dd5
- homepage: https://securityonion.net · fetched 2026-08-29 · f4940a18affe
- site_page: https://securityonionsolutions.com/pro · fetched 2026-08-29 · 738a431b1f51
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Security-Onion-Solutions/securityonion | main | 94 |
| Security-Onion-Solutions/security-onion | mirror | 10 |
For agents
markdown · JSON · MCP: product_card(name="Security-Onion-Solutions/securityonion")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem