Cybersecurity Detection Lab: Installing Security Onion V2

Поділитися
Вставка
  • Опубліковано 2 жов 2024

КОМЕНТАРІ • 59

  • @DayCyberwox
    @DayCyberwox  3 роки тому +10

    Don't forget to take snapshots for SecOnion & SecOnionMgmt!

  • @osamazidan7292
    @osamazidan7292 3 роки тому +5

    Hey, Linux folks =D
    I'm building this lab using KVM/QEMU on arch linux host.

  • @miyukinakiri7742
    @miyukinakiri7742 2 роки тому +5

    Hello, I have already done the so-allow, but when I tried to go into security onion address on ubuntu, it just shows me a 401 error authorization required

    • @silence6605
      @silence6605 Рік тому

      Did you ever resolve this?

    • @lifetimeumrah7220
      @lifetimeumrah7220 Рік тому +1

      @@silence6605 update security onion using (sudo soup) then wait 5 min and do (sudo so-status) if you have ok to all services then u goot to go

  • @rijinmp
    @rijinmp 3 роки тому +2

    Neat and cristal clear presentation 👌

  • @yahairairizarry2333
    @yahairairizarry2333 Рік тому +6

    for anyone who is unable to connect to the security onion ip from the sec analyst device like i was, take a look at the management ip that's in the screenshot you took from the screen at 10:03. use this instead of the ip address that ifconfig gives you.

    • @kamranfayaz5301
      @kamranfayaz5301 5 місяців тому

      unfortunately for me both are same. And i'm not able to connect to web interface. I searched the whole internet. Any suggestions??

  • @bwip2033
    @bwip2033 3 роки тому +10

    I've been working through this setup today and I was stuck here (confused myself with the network interfaces because I'm setting it up with VirtualBox). Wish you'd dropped this a few hours ago, haha! Keep em coming man. Awesome content.

    • @DayCyberwox
      @DayCyberwox  3 роки тому +3

      I actually had this planned for Friday, glad I dropped it earlier!

  • @fahadusman3538
    @fahadusman3538 2 роки тому +5

    192.168.135.X network not shown on your diagram. The ubuntu machine also gets the 192.168.135.X address and the Security Onion also gets a DHCP address in the same range. Please update your diagram.

  • @christ5687
    @christ5687 3 місяці тому +1

    VMWare does not allow you to select a guest OS anymore, it automatically detects it and its not CentOS7. The security onion installation also does not have alot of the same steps anymore. It doesnt ask for home networks or Bond NICs. I hope it still is set up fine, I followed as closely as possible. Thanks for the tutorial

  • @shardulgovekar2469
    @shardulgovekar2469 2 роки тому +2

    I have used the so-allow command to connect to my kali but then also I am getting the error, the proxy server is refusing connection . Any suggestions what can I do?

  • @infosec1065
    @infosec1065 Рік тому +2

    Holy f$%^n sheet dude, I have been trying to install this for days, your vid popped up outa nowhere and it worked!!! You sir do rock :)

  • @jakesullivan2696
    @jakesullivan2696 2 роки тому +2

    SecOnion web interface will not load even though i have entered everything correctly and so-status says everything is up and running help please

  • @Kandufilms
    @Kandufilms 3 роки тому +3

    Thanks Can't wait to try this!

  • @Jupiterxice
    @Jupiterxice 3 роки тому +2

    You the man............................

  • @e281tangy
    @e281tangy 3 місяці тому +1

    dude, thanks for taking the time to make these!

  • @barry3792
    @barry3792 2 роки тому +2

    Anybody know why I am stuck at running post-installation scripts? I know this vid dropped a year ago, but I just recently came across this channel. One issue might be the size of the iso according to one google answer. Thanks for the instruction, it's wonderful!

    • @Lantyyyy
      @Lantyyyy Рік тому

      Do you ever figure out the fix?

    • @barry3792
      @barry3792 Рік тому

      @@Lantyyyy Nah, gave up on that

  • @ixbo
    @ixbo Рік тому +1

    Even though i put the ubuntu desktop's ip as "analyst", it still cant access the site? is it na ip issue?

  • @SecurityNinja
    @SecurityNinja 3 роки тому +4

    Good content

  • @slydawg0811
    @slydawg0811 3 роки тому +2

    Hello Day I’ve installed security onion on my VMware to do the malware analysis. When I triple click the link to view the analysis it will time out. I can ping the up address but can’t pull up the site. Any suggestions?

    • @DayCyberwox
      @DayCyberwox  3 роки тому +1

      What URL are you using? Is it the URL containing the IP address of the SecOnion machine?

    • @slydawg0811
      @slydawg0811 3 роки тому

      Yes it has the up of the vm it it. It’s strange because I can ping the ip from the analyst machine but it times out when trying to pull it up

    • @DayCyberwox
      @DayCyberwox  3 роки тому

      Have your tried restarting the SecOnion machine?

    • @slydawg0811
      @slydawg0811 3 роки тому +1

      I will try that. Thanks!!!

    • @DayCyberwox
      @DayCyberwox  3 роки тому +1

      No problems! Check out the discord link in my bio and join so I can help troubleshoot better.🙂

  • @MichalŠkoda-u7t
    @MichalŠkoda-u7t 24 дні тому

    Hello, Ive got one question... How do you know which interface like enp0s# is which vmnet# thank you...

  • @calvinoliver4811
    @calvinoliver4811 Рік тому +1

    Awesome video. Thanks a lot.

  • @uncleebitu
    @uncleebitu 8 місяців тому

    I'm stuck here my VirtualBox won't load ISO file during installation, can you help?

  • @kennuffff
    @kennuffff 6 місяців тому

    Hey Cyberwox,
    I’m getting stuck during the post-installation scripts. Every time it finishes “installing”, it would hang and get stuck on the part where it says post installation scripts. Any idea how to fix this. I figured my specs was the issue but I tried using 16 gb ram and 300 gb of storage with 4 processors but still having the same issue.

  • @talishgarg8492
    @talishgarg8492 2 роки тому +1

    Hi, I tried installing the latest version of Security Onion, and it's stuck at running post-installation scripts. I have not been able to fix this issue. It would be great if you could help me with this. Thank you

  • @adrianomilan8589
    @adrianomilan8589 Рік тому

    hello defender , im having a smal problem when i submit the email *gmail * it says invalid account

  • @madshorts9074
    @madshorts9074 Рік тому

    I got error of "no default ui configuration directive found" can you please explain!!

  • @andrewlarson100
    @andrewlarson100 Рік тому

    Do you know I would be seeing ens32 showing down when I followed your video to a tee

  • @teknic111
    @teknic111 3 роки тому

    Is there a guide for setting up endpoints to be monitored? Would like to install monitoring agents on my windows and Linux machines.

  • @christ5687
    @christ5687 3 місяці тому

    in security onion, when I type sudo so-allow. it says Please use the Configuration section in SOC to allow hosts

    • @christ5687
      @christ5687 3 місяці тому

      apparently security onion 2.4 does not run on centos 7. Also the so-allow command is deprecated and all of the firewall settings is done via the online interface. Unfortunately, firefox times out everytime i try to access the web interface on the ubuntu VM. If anyone else is trying to get this done in 2024, let me know. thanks

    • @everythingmajor5639
      @everythingmajor5639 3 місяці тому

      @@christ5687 I have similar issue. During install, it shows a loop stating that the sobridge port 13 has entered blocking state and disabled state. If you find a fix, please help

    • @e281tangy
      @e281tangy 3 місяці тому

      @@christ5687 thanks for the info. I will try to install it on a RHEL9 box...hopefully it works

  • @fridaygodwin3617
    @fridaygodwin3617 Рік тому

    i have an issue with installing the sec onion the error message is operating system not found

  • @kylerthibeault3950
    @kylerthibeault3950 Рік тому

    When setting up security onion, I’m getting ENS33 showing Link Down. How to fix?

  • @zuberkariye2299
    @zuberkariye2299 3 роки тому +3

    I love SecOnion interface and the default tools that come with it, I don't have a powerful computer that I can use right now, so I will buy a server or something. Can SecOnion use in real enterprise companies! This is one of my great vid. One more question, how will this tool detect attacks from Kali, so they just need to be on the same network (LAN) and then that means they will be able to talk to each other w/o doing any configuration? Thanks again!

    • @DayCyberwox
      @DayCyberwox  3 роки тому +3

      You don’t have to have a powerful server to use security onion! With security onions so-import coal option you can run it with just 4Gb RAM and start doing hunts with PCAP samples from malware analysis dot net. If you’re interested in this I can show how to get started with it 🙂.
      In terms of detecting attacks from Kali, I’m gonna have windows and Linux endpoints using either syslog or elastic winbeats to feed logs to kibana on security onion and see what attacks are being run from Kali. This is in the scope of the project.

    • @collinsnwanze8502
      @collinsnwanze8502 3 роки тому +1

      @@DayCyberwox please how can I run it with less RAM

    • @DayCyberwox
      @DayCyberwox  3 роки тому +1

      @@collinsnwanze8502 Here you go: ua-cam.com/video/mgdbJApNfuQ/v-deo.html

    • @collinsnwanze8502
      @collinsnwanze8502 3 роки тому +1

      @@DayCyberwox Thank you. I have not slept for 2days trying to go around it. bought an hard drive today but still not working

  • @kashishjairath2335
    @kashishjairath2335 Рік тому

    how much did it took you install sec onion? my installation is just stuck at "post installation scripts" and it s not moving forward

    • @christ5687
      @christ5687 3 місяці тому

      it probably ran an hour or more before it finally installed on mine

  • @mohammadrasi3366
    @mohammadrasi3366 Рік тому

    Hey body
    I have a problem while I set up my virtual machine
    So when I want to choose my iso file which is security onion I take this response you don't have permission to open this file
    Contact the file owner or an administrator to obtain permission !!
    I need this
    I'll be thankful for the response 🙏❤️

  • @jhonsonpedroza3555
    @jhonsonpedroza3555 2 роки тому

    excelente ayuda muchas gracias