Free
Security Onion
Security Onion is an open-source Network Security Monitoring and log management Linux Distribution. In this Security Onion course, you will explore the history, components, and architecture of the distro to improve your networking skills. Learn how to install and deploy server architectures, as well as how to replay or sniff traffic.
3
H
10
M
Time
beginner
difficulty
3
ceu/cpe
Course Content
11.1 Course Wrap Up
Module 11: Wrap Up
1.1 Introduction
Module 1: Introduction
2.1 What is Security Onion?
Module 2: What is Security Onion?
3.1 Security Onion Download and Installation Part 1
Module 3: Installing a Standalone Server
4.1 Server Configuration Demo Part 1
Module 4: Installing a Distributed Environment
5.1 Server Installation Review
Module 5: Reviewing the Installation
6.1 Resources Part 1
Module 6: Resources
7.1 TCPReplay Part 1
Module 7: Replaying Traffic on a Standalone Server
8.1 Sniffing Traffic
Module 8: Sniffing Traffic in a Distributed Environment
9.1 Lesson 9 Agenda
Module 9: Management Tips and Best Practices
10.1 Lesson 10 Overview
Module 10: Other Functionality
2.2 Monitoring and Analysis Tools
Module 2: What is Security Onion?
3.2 Security Onion Download and Installation Part 2
Module 3: Installing a Standalone Server
4.2 Server Configuration Demo Part 2
Module 4: Installing a Distributed Environment
5.2 Checking System Services With sostat
Module 5: Reviewing the Installation
6.2 Resources Part 2
Module 6: Resources
7.2 TCPReplay Part 2
Module 7: Replaying Traffic on a Standalone Server
8.2 Traffic Overview in Kibana
Module 8: Sniffing Traffic in a Distributed Environment
9.2 Salt Tips
Module 9: Management Tips and Best Practices
10.2 Wazuh/OSSEC Functionality
Module 10: Other Functionality
2.3 Security Onion Architecture
Module 2: What is Security Onion?
4.3 Server Configuration Demo Part 3
Module 4: Installing a Distributed Environment
5.3 Security Onion Web Browser Tools
Module 5: Reviewing the Installation
7.3 TCPReplay Part 3
Module 7: Replaying Traffic on a Standalone Server
8.3 SSH Success
Module 8: Sniffing Traffic in a Distributed Environment
Course Description
Overall, this course will allow you to learn how to maintain and update Security Onion.
Students should have networking knowledge (TCP/IP, Protocols, Packets, etc.), linux knowledge (mkdir, Is, vi, ifconfig, etc.), and security technology knowledge (IDS, Full Packet Capture, etc).