Ross ROSS = Recommend OSS · open-source software intelligence for agents

Security Onion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek. observed · 2026-08-28

github.com/Security-Onion-Solutions/securityonion · homepage · Shell · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 99
  • Release rhythm 83
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 34.0
  • age_days: 3131
  • days_rel: 35
  • days_push: 7
  • n_releases_24m: 23

Full methodology

Adoption not part of the score

4846 stars · 670 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Security Onion is a free and open Linux distribution and platform for threat hunting, enterprise security monitoring, and log management. It bundles a unified web console (SOC) with Suricata, Zeek, the Elastic Stack, full packet capture, detections, and case management.

Use cases

  • monitor enterprise network security events
  • hunt threats with full packet capture and Zeek metadata
  • run network intrusion detection with Suricata
  • centralize and search security logs
  • manage alert triage and investigations with case management
  • set up a self-hosted SOC on Linux

When to choose

  • you need an all-in-one, self-hosted network security monitoring and IDS platform
  • you want Suricata, Zeek, and the Elastic Stack pre-integrated and maintained for you
  • you need packet capture, alerting, dashboards, and case management in one console
  • you are a SOC, government, or enterprise team doing threat hunting

When to avoid

  • you only need a lightweight host-based antivirus or endpoint agent
  • you want a fully managed cloud SIEM with no infrastructure to run
  • you cannot dedicate the substantial hardware resources Security Onion requires
  • you need a simple log shipper rather than a full monitoring distribution

Facets

application · maturity stable

monitoring search-engine logging security alerting analytics security networking monitoring self-hosted developer-tools self-hosted cloud threat-hunting intrusion-detection network-security-monitoring suricata zeek elastic-stack pcap case-management siem log-management linux docker web-server

3 sources

Member repositories

For agents

markdown · JSON · MCP: product_card(name="Security-Onion-Solutions/securityonion")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem