security-onion-solutions/securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for...

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 31 minutes ago
Added to GitGenius on September 14th, 2026
Created on February 5th, 2018
Open Issues & Pull Requests: 78 (+0)
GitHub issues: Enabled
Number of forks: 676
Total Stargazers: 4,890 (+0)
Total Subscribers: 99 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 0.0 hours
Mean response time: 12.6 days
90th percentile: 23.2 hours
Tracked items: 568

Most active contributors

Sign in to see contributor activity.

How this project is maintained

About 4% of issues opened in the past year have never received a reply. 100% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Work labelled "Detections" is answered fastest, typically in under an hour, while "2.4" waits about 3 days. 90% of issues opened in the past year have since been closed. Three people close 59% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 50
New in 7 days: 5
Closed in 7 days: 3
Avg open age: 319 days
Stale 30+ days: 31
Stale 90+ days: 26

Recent activity

Opened in 7 days: 5
Closed in 7 days: 3
Comments in 7 days: 0
Events in 7 days: 5

Top labels

  • SOC (57)
  • Detections (12)
  • PCAP (12)
  • 2.4 (11)
  • bug (8)
  • Alerts (6)
  • Cases (3)
  • Hunt (3)

Detailed Description

Security Onion is a free and open Linux distribution for threat hunting, enterprise security monitoring, and log management.

The tool addresses the need for comprehensive network and host visibility by bundling detection, analysis, and investigation capabilities into a single platform. It combines network-based intrusion detection through Suricata, host-based monitoring via Elastic Fleet, and network metadata generation from Zeek or Suricata. The Security Onion Console provides a unified web interface for analyzing security events, while the Elastic Stack powers search and log management. Full packet capture retention enables raw network traffic analysis when needed.

Organizations should choose this tool if they need an integrated security monitoring platform that combines multiple detection and analysis functions without requiring separate tool integration. It suits enterprises and security teams operating their own infrastructure, particularly those wanting to avoid vendor lock-in through its open-source foundation. The platform is available as a downloadable ISO for on-premises deployment and through cloud marketplaces for AWS, Azure, and Google Cloud. A commercial Pro tier offers AI-driven analysis and enterprise-grade features for organizations requiring advanced capabilities at scale.

The project maintains active development with regular updates documented in release notes. Documentation is comprehensive and includes hardware requirements guidance, installation instructions, and a frequently asked questions section. The team provides official training resources and maintains community support channels for user questions and discussions. Contributions are welcomed through established guidelines, indicating ongoing community engagement with the codebase.