Back to distribution list Public statistics

Security onion 3.2.0

Official Linux ISO download for 64-bit systems.
Desktop

About Security onion

Security Onion is a free and open platform built by defenders for defenders. It includes network visibility, host visibility, intrusion detection honeypots, log management, and case management.For network visibility, we offer signature based detection via Suricata, rich protocol metadata and file extraction using your choice of either Zeek or Suricata, full packet capture via Suricata PCAP, and file analysis via Strelka. For host visibility, we offer the Elastic Agent which provides data collection, live queries via osquery, and centralized management using Elastic Fleet. Intrusion detection honeypots based on OpenCanary can be added to your deployment for even more enterprise visibility. All of these logs flow into the Elastic stack and we've built our own user interfaces for alerting, hunting, dashboards, case management, and grid management.

Security onion 3.2.0 is recorded with Debian as its base. The listed desktop environment is GNOME. It is grouped under Desktop.

Release3.2.0
BaseDebian
Desktop environmentGNOME
CategoriesDesktop
Server imageNot listed

Available images and downloads

Current download methods recorded for Security onion include desktop ISO. Choose the image that matches your architecture and intended use.

For release notes, installation documentation and project-specific requirements, use the official Security onion website. IsosLinux links to the upstream project instead of replacing its documentation.

Verify the ISO

After downloading an ISO, verify its checksum against the value published by the distribution whenever one is available. A matching SHA-256 or SHA-512 checksum helps confirm that the file was transferred correctly and has not changed. You can use the IsosLinux ISO Checksum Verifier or the standard sha256sum and sha512sum commands on Linux.

Open the ISO Checksum Verifier

Create installation media

To install Security onion, write the downloaded image to a USB drive with a trusted imaging tool such as Ventoy, Rufus, balenaEtcher or a distribution-specific writer. Always verify the target drive before writing because the process normally erases its existing contents.

Frequently asked questions

What is Security onion?

Security Onion is a free and open platform built by defenders for defenders. It includes network visibility, host visibility, intrusion detection honeypots, log management, and case management.For network visibility, we offer signature based detection via Suricata, rich protocol metadata and file extraction using your choice of either Zeek or Suricata, full packet capture via Suricata PCAP, and file analysis via Strelka. For host visibility, we offer the Elastic Agent which provides data collection, live queries via osquery, and centralized management using Elastic Fleet. Intrusion detection honeypots based on OpenCanary can be added to your deployment for even more enterprise visibility. All of these logs flow into the Elastic stack and we've built our own user interfaces for alerting, hunting, dashboards, case management, and grid management.

Where should I download Security onion?

Use the official project source linked on this page. IsosLinux may also provide direct links that point to project or mirror infrastructure.

Should I verify the ISO before installing it?

Yes. When the project publishes a checksum, compare it with the checksum of your downloaded file before creating installation media.

Which desktop environment is listed for Security onion?

The current IsosLinux catalog lists GNOME for this distribution.

Related distributions

Explore other distributions with a similar base, categories or desktop environment.

12
Total downloads
12
Desktop downloads
0
Server downloads

Description

Security Onion is a free and open platform built by defenders for defenders. It includes network visibility, host visibility, intrusion detection honeypots, log management, and case management.For network visibility, we offer signature based detection via Suricata, rich protocol metadata and file extraction using your choice of either Zeek or Suricata, full packet capture via Suricata PCAP, and file analysis via Strelka. For host visibility, we offer the Elastic Agent which provides data collection, live queries via osquery, and centralized management using Elastic Fleet. Intrusion detection honeypots based on OpenCanary can be added to your deployment for even more enterprise visibility. All of these logs flow into the Elastic stack and we've built our own user interfaces for alerting, hunting, dashboards, case management, and grid management.

Distribution details

Based on: debian

Categories: Desktop

Safe download

The download button first records an anonymous aggregated download counter and then redirects to the official source.