Skip to content
OpenCatalogcurated by FLOSSK
Security & Privacy

Security Onion

Linux distribution and platform bundling Zeek, Suricata, Elastic stack, and analyst UIs for NSM and log hunting.

Why it is included

Turnkey open blueprint for SOC-in-a-box labs and small teams.

Best for

Homelab SOCs, training, and pilots before enterprise SIEM spend.

Strengths

  • Integrated stack
  • Curated updates
  • Community

Limitations

  • Hardware sizing; overlaps with custom ELK + Zeek builds

Good alternatives

Wazuh + Elastic · custom Zeek/Suricata

Related tools