Security Onion 2 Fundamentals for Analysts & Admins - Virtual June 2021

Actions and Detail Panel


Event Information

Share this event

Date and Time



Online Event

Refund Policy

Refund Policy

Contact the organizer to request a refund.

Eventbrite's fee is nonrefundable.

Event description
Learn how to architect, manage, deploy, and effectively use Security Onion 2 in this 4-day course delivered virtually, June 7-10, 2021.

About this Event

About Security Onion 2

Security Onion 2 is a free and open source Linux distribution for threat hunting, enterprise security monitoring, and log management. It includes TheHive, Playbook & Sigma, Fleet & Osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, Zeek, Wazuh, and many other security tools. Security Onion has been downloaded over 2 million times and is being used by security teams around the world to monitor and defend their enterprises. Our easy-to-use Setup wizard allows you to build an army of distributed sensors for your enterprise in minutes!

For more about Security Onion, please see https://securityonionsolutions.com

About the Course

This course is geared for analysts and administrators of Security Onion 2 (formerly Hybrid Hunter). Students will gain a foundational understanding of this new platform - how to architect, deploy, and manage their Security Onion 2 grid. The course also covers major analyst workflows, reinforced through real-world case studies.

  • 4 full days of class instruction from the developers of Security Onion 2
  • 300+ pages of course material
  • Certificate of Completion delivered electronically

When is the class?

Monday, June 7, 2021 through Thursday, June 10, 2021

8-hour class from 8:00 AM - 5:00 PM (Eastern Time) each day

When does registration close?

Registration closes Wednesday, May 26, at 11:59 PM Eastern.

Where is the class being held?

The class is being held virtually via WebEx.

What hardware, etc. will be required for the class?

Students will need a computer with a browser and Internet access.

Please check your machine's ability to participate in the course before registering: https://securityonionsolutions.com/precheck

Contact us with any questions about these requirements.

Which version of Security Onion will we be using?

We'll be using the latest stable Security Onion 2 release as of May 15.

The latest stable release can be found here: https://securityonion.net/download

What skills/knowledge should students have before attending this course?

Students should attend the free 2-hour Security Onion Essentials course before the first day of class.

Students should have a basic understanding of networks, TCP/IP, and standard protocols such as DNS, HTTP, etc.  Some Linux knowledge/experience is recommended, but not required.

What's the cancellation policy?

Security Onion Solutions reserves the right to cancel this class up to one day after registration closes if the class does not meet a minimum number of students. If class is canceled, the training ticket cost will be refunded.

What's the refund policy?

You may log into your Eventbrite account to request a refund up until the last day of ticket sales.  Please use the "Request a Refund" button as shown here: https://www.eventbrite.com/support/articles/en_US/How_To/can-i-get-a-refund

Are there discounts available?

For this course, we are offering a discount to active duty US military and active US Federal employees. We also offer discounts to members of ISSA and Infragard. Contact us for more information.

What topics are covered in this class?

Note: Syllabus is subject to change

  • Security Onion Console
  • Security Onion 2 System Architecture
  • Deploying a Security Onion 2 Distributed Architecture
  • Common Administrative Tasks
  • Security Onion 2 Workflows
    • Alert Triage & Case Creation with SOC Alerts and TheHive
    • Ad hoc Hunting with Kibana and SOC Hunt
    • Detection Engineering with Playbook
  • Grid Management
    • Users
    • Firewalls
    • Updating
    • Monitoring
    • Troubleshooting
    • Hardening
  • Tuning the Grid
    • Berkeley Packet Filters
    • Performance Tuning - Zeek and Suricata
    • Alert Tuning - Suricata and Playbook
  • Integrating Endpoint Data with Osquery and Wazuh
  • Zeek
    • Logs
    • Scripts
    • Intel Framework
  • Creating Custom Dashboards with Kibana
  • Alternative Deployment Architectures
    • Airgap Deployments
    • Cloud Deployments
  • Multiple Labs and Case Studies

Share with friends

Date and Time


Online Event

Refund Policy

Contact the organizer to request a refund.

Eventbrite's fee is nonrefundable.

Save This Event

Event Saved