COURSE

Security Onion

Course

Security Onion is an open-source Network Security Monitoring and log management Linux Distribution. In this Security Onion course, you will explore the history, components, and architecture of the distro to improve your networking skills. Learn how to install and deploy server architectures, as well as how to replay or sniff traffic.
Full access included with 
Insider Pro
 and 
Teams

3

H

10

M
Time

beginner

i
Designed for learners who have no prior work experience in IT or Cybersecurity, but are interested in starting a career in this exciting field.
Designed for learners with prior cybersecurity work experience who are interested in advancing their career or expanding their skillset.
Designed for learners with a solid grasp of foundational IT and cybersecurity concepts who are interested in pursuing an entry-level security role.
Experience Level

3

i

Earn qualifying credits for certification renewal with completion certificates provided for submission.
CEU's

Enrollees

Learners at 96% of Fortune 1000 companies trust Cybrary

About this course

Read More

Skills you'll gain

Course Outline

1
Module 1: Introduction
0
H
4
Min
1
Module 2: What is Security Onion?
0
H
20
Min
1
Module 3: Installing a Standalone Server
0
H
20
Min
1
Module 4: Installing a Distributed Environment
0
H
29
Min
1
Module 5: Reviewing the Installation
0
H
20
Min
1
Module 6: Resources
0
H
10
Min
1
Module 7: Replaying Traffic on a Standalone Server
0
H
37
Min
1
Module 8: Sniffing Traffic in a Distributed Environment
0
H
17
Min
1
Module 9: Management Tips and Best Practices
0
H
26
Min
1
Module 10: Other Functionality
0
H
5
Min
1
Module 11: Wrap Up
0
H
2
Min

10.1 Lesson 10 Overview

Free

1m

8.1 Sniffing Traffic

Free

4m

9.1 Lesson 9 Agenda

Free

1m

5.1 Server Installation Review

Free

2m

7.1 TCPReplay Part 1

Free

2m

6.1 Resources Part 1

Free

6m

2.1 What is Security Onion?

Free

5m

1.1 Introduction

Free

4m

4.1 Server Configuration Demo Part 1

Free

4m

3.1 Security Onion Download and Installation Part 1

Free

10m

11.1 Course Wrap Up

Free

2m

10.2 Wazuh/OSSEC Functionality

Free

1m

8.2 Traffic Overview in Kibana

Free

13m

9.2 Salt Tips

Free

5m

6.2 Resources Part 2

Free

4m

5.2 Checking System Services With sostat

Free

5m

7.2 TCPReplay Part 2

Free

17m

3.2 Security Onion Download and Installation Part 2

Free

11m

2.2 Monitoring and Analysis Tools

Free

4m

4.2 Server Configuration Demo Part 2

Free

11m

10.3 DNS Anomaly Detection Script

Free

1m

8.3 SSH Success

Free

1m

7.3 TCPReplay Part 3

Free

18m

4.3 Server Configuration Demo Part 3

Free

14m

5.3 Security Onion Web Browser Tools

Free

9m

2.3 Security Onion Architecture

Free

7m

10.4 Domain Stats and Frequency Server

Free

2m

9.4 IDS Rules Management

Free

9m

7.4 Review

Free

1m

5.4 Security Onion Terminal

Free

3m

2.4 Deployment Types

Free

3m

9.6 Other Helpful Commands and Tips

Free

4m

10.1 Lesson 10 Overview

1m

Module 10: Other Functionality
8.1 Sniffing Traffic

4m

Module 8: Sniffing Traffic in a Distributed Environment
9.1 Lesson 9 Agenda

1m

Module 9: Management Tips and Best Practices
5.1 Server Installation Review

2m

Module 5: Reviewing the Installation
7.1 TCPReplay Part 1

2m

Module 7: Replaying Traffic on a Standalone Server
6.1 Resources Part 1

6m

Module 6: Resources
2.1 What is Security Onion?

5m

Module 2: What is Security Onion?
1.1 Introduction

4m

Module 1: Introduction
4.1 Server Configuration Demo Part 1

4m

Module 4: Installing a Distributed Environment
3.1 Security Onion Download and Installation Part 1

10m

Module 3: Installing a Standalone Server
11.1 Course Wrap Up

2m

Module 11: Wrap Up
10.2 Wazuh/OSSEC Functionality

1m

Module 10: Other Functionality
8.2 Traffic Overview in Kibana

13m

Module 8: Sniffing Traffic in a Distributed Environment
9.2 Salt Tips

5m

Module 9: Management Tips and Best Practices
6.2 Resources Part 2

4m

Module 6: Resources
5.2 Checking System Services With sostat

5m

Module 5: Reviewing the Installation
7.2 TCPReplay Part 2

17m

Module 7: Replaying Traffic on a Standalone Server
3.2 Security Onion Download and Installation Part 2

11m

Module 3: Installing a Standalone Server
2.2 Monitoring and Analysis Tools

4m

Module 2: What is Security Onion?
4.2 Server Configuration Demo Part 2

11m

Module 4: Installing a Distributed Environment
10.3 DNS Anomaly Detection Script

1m

Module 10: Other Functionality
8.3 SSH Success

1m

Module 8: Sniffing Traffic in a Distributed Environment
7.3 TCPReplay Part 3

18m

Module 7: Replaying Traffic on a Standalone Server
4.3 Server Configuration Demo Part 3

14m

Module 4: Installing a Distributed Environment
5.3 Security Onion Web Browser Tools

9m

Module 5: Reviewing the Installation
Course Description

Overall, this course will allow you to learn how to maintain and update Security Onion.

Students should have networking knowledge (TCP/IP, Protocols, Packets, etc.), linux knowledge (mkdir, Is, vi, ifconfig, etc.), and security technology knowledge (IDS, Full Packet Capture, etc).

Train Your Team

Cybrary’s expert-led cybersecurity courses help your team remediate skill gaps and get up-to-date on certifications. Utilize Cybrary to stay ahead of emerging threats and provide team members with clarity on how to learn, grow, and advance their careers within your organization.

Included in a Path

Instructors

Karl Hansen
Senior SOC Analyst
Read Full Bio
Learn

Learn core concepts and get hands-on with key skills.

Practice

Exercise your problem-solving and creative thinking skills with security-centric puzzles

Prove

Assess your knowledge and skills to identify areas for improvement and measure your growth

Get Hands-on Learning

Put your skills to the test in virtual labs, challenges, and simulated environments.

Measure Your Progress

Track your skills development from lesson to lesson using the Cybrary Skills Tracker.

Connect with the Community

Connect with peers and mentors through our supportive community of cybersecurity professionals.

Success from Our Learners

"Cybrary really helped me get up to speed and acquire a baseline level of technical knowledge. It offers a far more comprehensive approach than just learning from a book. It actually shows you how to apply cybersecurity processes in a hands-on way"

Don Gates

Principal Systems Engineer/SAIC

"Cybrary’s SOC Analyst career path was the difference maker, and was instrumental in me landing my new job. I was able to show the employer that I had the right knowledge and the hands-on skills to execute the role."

Cory

Cybersecurity analyst/

"I was able to earn my CISSP certification within 60 days of signing up for Cybrary Insider Pro and got hired as a Security Analyst conducting security assessments and penetration testing within 120 days. This certainly wouldn’t have been possible without the support of the Cybrary mentor community."

Mike

Security Engineer and Pentester/

"Cybrary really helped me get up to speed and acquire a baseline level of technical knowledge. It offers a far more comprehensive approach than just learning from a book. It actually shows you how to apply cybersecurity processes in a hands-on way"

Don Gates

Principal Systems Engineer/SAIC

"Cybrary’s SOC Analyst career path was the difference maker, and was instrumental in me landing my new job. I was able to show the employer that I had the right knowledge and the hands-on skills to execute the role."

Cory

Cybersecurity analyst/

"I was able to earn my CISSP certification within 60 days of signing up for Cybrary Insider Pro and got hired as a Security Analyst conducting security assessments and penetration testing within 120 days. This certainly wouldn’t have been possible without the support of the Cybrary mentor community."

Mike

Security Engineer and Pentester/

"Becoming a Cybrary Insider Pro was a total game changer. Cybrary was instrumental in helping me break into cybersecurity, despite having no prior IT experience or security-related degree. Their career paths gave me clear direction, the instructors had real-world experience, and the virtual labs let me gain hands-on skills I could confidently put on my resume and speak to in interviews."

Cassandra

Information Security Analyst/Cisco Systems

"I was able to earn both my Security+ and CySA+ in two months. I give all the credit to Cybrary. I’m also proud to announce I recently accepted a job as a Cyber Systems Engineer at BDO... I always try to debunk the idea that you can't get a job without experience or a degree."

Casey

Cyber Systems Engineer/BDO

"Cybrary has helped me improve my hands-on skills and pass my toughest certification exams, enabling me to achieve 13 advanced certifications and successfully launch my own business. I love the practice tests for certification exams, especially, and appreciate the wide-ranging training options that let me find the best fit for my goals"

Angel

Founder,/ IntellChromatics.

Security Onion

Security Onion is an open-source Network Security Monitoring and log management Linux Distribution. In this Security Onion course, you will explore the history, components, and architecture of the distro to improve your networking skills. Learn how to install and deploy server architectures, as well as how to replay or sniff traffic.
3
10
M
Time
beginner
difficulty
3
ceu/cpe

Course Content

Course Description

Overall, this course will allow you to learn how to maintain and update Security Onion.

Students should have networking knowledge (TCP/IP, Protocols, Packets, etc.), linux knowledge (mkdir, Is, vi, ifconfig, etc.), and security technology knowledge (IDS, Full Packet Capture, etc).

This course is part of a Career Path:
No items found.

Instructed by

Provider
Cybrary Logo
Certification Body
Certificate of Completion

Complete this entire course to earn a Security Onion Certificate of Completion