Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. App Wishlist
  3. Security Onion for threat hunting, network security monitoring, and log management.

Security Onion for threat hunting, network security monitoring, and log management.

Scheduled Pinned Locked Moved App Wishlist
5 Posts 3 Posters 1.0k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      D Offline
      Dark Shadow
      wrote on last edited by
      #1

      Security Onion, is a free and open platform for threat hunting, network security monitoring, and log management. Security Onion includes free and open tools including Suricata, Zeek, Wazuh, the Elastic Stack and many others.

      https://github.com/Security-Onion-Solutions/securityonion/blob/master/VERIFY_ISO.md

      M 1 Reply Last reply
      0
      • D Dark Shadow

        Security Onion, is a free and open platform for threat hunting, network security monitoring, and log management. Security Onion includes free and open tools including Suricata, Zeek, Wazuh, the Elastic Stack and many others.

        https://github.com/Security-Onion-Solutions/securityonion/blob/master/VERIFY_ISO.md

        M Offline
        M Offline
        Mastadamus
        wrote on last edited by
        #2

        @dark-shadow I run security onion on a separate machine. I don't think its applicable for cloudron. 1. it can't be containerized. its a stack of docker containers controlled by SALT. 2. It requires immense CPU/RAM/HD. For a small network you are looking at 4 cores min and at least 20gb ram. Additionally, You don't really want to put your security tools on the same subnet as your internet facing stuff.

        robiR 1 Reply Last reply
        1
        • M Mastadamus

          @dark-shadow I run security onion on a separate machine. I don't think its applicable for cloudron. 1. it can't be containerized. its a stack of docker containers controlled by SALT. 2. It requires immense CPU/RAM/HD. For a small network you are looking at 4 cores min and at least 20gb ram. Additionally, You don't really want to put your security tools on the same subnet as your internet facing stuff.

          robiR Offline
          robiR Offline
          robi
          wrote on last edited by
          #3

          @mastadamus This is possible because of a few innovations:

          1. Sysbox by Nestybox, find the thread in this forum.
          2. This allows for Docker-in-Docker nesting, even running VMs.
          3. With affordable VPS providers like SSDnodes and Contabo, CPU and RAM are not an issue.
          4. With multi-cloudron coming soon, it's going to be an ecosystem of hosts managed by a central Cloudron UI, so why not have a host dedicated to security or similar functions.

          Conscious tech

          M 1 Reply Last reply
          0
          • robiR robi

            @mastadamus This is possible because of a few innovations:

            1. Sysbox by Nestybox, find the thread in this forum.
            2. This allows for Docker-in-Docker nesting, even running VMs.
            3. With affordable VPS providers like SSDnodes and Contabo, CPU and RAM are not an issue.
            4. With multi-cloudron coming soon, it's going to be an ecosystem of hosts managed by a central Cloudron UI, so why not have a host dedicated to security or similar functions.
            M Offline
            M Offline
            Mastadamus
            wrote on last edited by
            #4

            @robi yeah I should have said "can't be easily containerized"
            Security onion relies on a span port/mirror traffic getting to its analysis engines and is a pretty complicated beast. If cloudron can containerized the whole thing awesome but this is no small task lol.

            robiR 1 Reply Last reply
            1
            • M Mastadamus

              @robi yeah I should have said "can't be easily containerized"
              Security onion relies on a span port/mirror traffic getting to its analysis engines and is a pretty complicated beast. If cloudron can containerized the whole thing awesome but this is no small task lol.

              robiR Offline
              robiR Offline
              robi
              wrote on last edited by
              #5

              @mastadamus good convo to have with the Sysbox folks.

              Conscious tech

              1 Reply Last reply
              0
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


                • Login

                • Don't have an account? Register

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • Bookmarks
                • Search