Security Onion for Analysts and Threat Hunters Virtual - Apr 29-May 2, 2025

Schedule

Tue, 29 Apr, 2025 at 08:00 am to Fri, 02 May, 2025 at 05:00 pm

UTC-04:00

Location

Online | Online, 0

Advertisement
Learn core analyst techniques and how to apply them with Security Onion in this 4-day course, April 29 - May 2, 2025.
About this Event

About Security Onion

Security Onion is a free and open platform built by defenders for defenders. It includes network visibility, host visibility, intrusion detection honeypots, log management, and case management. Security Onion has been downloaded over 2.4 million times and is being used by security teams around the world to monitor and defend their enterprises. Our easy-to-use Setup wizard allows you to build a distributed grid for your enterprise in minutes!

For more about Security Onion, please see https://securityonion.com

About the Course

This hands-on course is geared for security analysts and threat hunters using the Security Onion platform, with very light coverage of administration. Students will learn core analyst techniques and how to apply them using real-world case studies covering major analyst workflows. Each student will receive:

  • 4 full days of class instruction from the developers of Security Onion
  • 300+ pages of course material
  • Certificate of Completion

When is the class?

Tuesday, April 29, 2025 through Friday, May 2, 2025

8-hour class with a one hour lunch from 8:00 AM - 5:00 PM (Eastern Time) each day

When does registration close?

Registration closes Thursday, April 10, 2025, at 11:59 PM US Eastern Time.

Where is the class being held?

The class is being held virtually via WebEx.

What hardware, etc. will be required for the class?

Students will need a computer with a browser and Internet access.

Please check your machine's ability to participate in the course before registering: https://securityonionsolutions.com/precheck

The precheck should report good or great internet speed and that your browser meets the requirements. Contact us with any questions.

Which version of Security Onion will we be using?

Our virtual lab environment will use the latest stable release of Security Onion as of April 10, 2025.

You don't need it for the class, but the latest stable release can be found here: https://securityonion.com/download

What skills/knowledge should students have before attending this course?

Students should attend the free 2-hour Security Onion Essentials course before the first day of class. One topic covered by this course is building a Security Onion VM. Note that students do not need to build a Security Onion VM for this class. We will be using a pre-installed virtual lab.

Students should have a basic understanding of networks, TCP/IP, and standard protocols such as DNS, HTTP, etc. Some Linux knowledge/experience is recommended, but not required.

What's the cancellation policy?

Security Onion Solutions reserves the right to cancel this class up to one day after registration closes if the class does not meet a minimum number of students. If class is canceled, the full training ticket cost will be refunded.

What's the refund policy?

You may log into your Eventbrite account to request a refund up until the last day of ticket sales. Note that the Eventbrite fees of $252.46 are not refundable unless you are refunded due to class cancellation. Please use the "Request a Refund" button as shown here: https://www.eventbrite.com/support/articles/en_US/How_To/can-i-get-a-refund

Are there discounts available?

For this course, we are offering a discount to active duty US military and active US Federal employees. Contact us for more information.

Does the class prepare students to pass the Security Onion Certified Professional (SOCP) exam?

In this class, students will use the interfaces in Security Onion to hunt for and respond to alerts on malicious activity. It is not intended to be a certification prep class.

What topics are covered in this class?

Note: Syllabus is subject to change

  • Security Onion Console Overview
  • Security Onion Grid Architecture
  • Basic Administrative Tasks
    + Manage User Accounts
    + Validate Grid Health
  • Crucial Network Protocols and Host-Based Datasets (HTTP, SSL, DNS, Windows, Sysmon, etc.)
  • Correlate Network and Host Data with Security Onion Console
  • Discuss SOC Analyst Methodologies
    + Key Elements of the Security Event Management Process
    + Incident Escalation and Resolution
    + Understanding the Analysis & Investigation Process
    + Leveraging the MITRE ATT&CK Framework to Improve Threat Hunting
  • Security Onion Analyst Workflows
    + Alert Triage & Case Creation with Alerts and Cases
    + Threat Hunting with Hunt and Dashboards
    + Detection Engineering
  • Searching for Data in Security Onion
    + Lucene
    + Onion Query Language (OQL)
  • Analyst Techniques
    + Analyzing and Reconstructing Obfuscated Executables from Packets
    + Finding Malicious Activity in Encrypted Traffic
    + Detecting Hostile DNS Traffic (DNS tunneling, C2 over DNS, etc.)
    + Tracking Adversary Activity Using Process Command Lines
    + Identifying Anomalies Utilizing Network and Host Baselines
  • Examining Data with CyberChef
  • Visualizing Enterprise Data
  • Capstone Capture the Flag Event
  • Multiple Labs and Case Studies
Advertisement

Where is it happening?

Online
Tickets

USD 3798.00

Security Onion Solutions LLC

Host or Publisher Security Onion Solutions LLC

It's more fun with friends. Share with friends

Discover More Events in Online

Monthly Grief Support Group: April 2025
Mon, 28 Apr, 2025 at 07:00 pm Monthly Grief Support Group: April 2025

Online

NONPROFIT CHARITIES
Subject Leadership Forum  3
Mon, 28 Apr, 2025 at 07:30 pm Subject Leadership Forum 3

Online

BUSINESS
Module 16 - Residential Experiences
Mon, 28 Apr, 2025 at 07:30 pm Module 16 - Residential Experiences

Online

WORKSHOPS
How to set up and run a party kit (8pm BST \/ 12pm PT \/ 3pm ET)
Mon, 28 Apr, 2025 at 08:00 pm How to set up and run a party kit (8pm BST / 12pm PT / 3pm ET)

Online

PARTIES ENTERTAINMENT
The SCERTS Model - Day 3 - Assessment
Tue, 29 Apr, 2025 at 09:00 am The SCERTS Model - Day 3 - Assessment

Online

WORKSHOPS VIRTUAL
LOVED - How to Rethink Product Marketing
Tue, 29 Apr, 2025 at 09:00 am LOVED - How to Rethink Product Marketing

Online

WORKSHOPS BUSINESS
Reporting of Contribution Revenue and Fundraising Events
Tue, 29 Apr, 2025 at 09:00 am Reporting of Contribution Revenue and Fundraising Events

Online

CHARITIES WORKSHOPS
Book Club by WorkLife Studios - 7L: The Seven Levels of Communication
Tue, 29 Apr, 2025 at 09:00 am Book Club by WorkLife Studios - 7L: The Seven Levels of Communication

Online

BUSINESS
ServSafe Food Handler Card - CALIFORNIA, DC, TEXAS AND ALL STATES - ONLINE
Sat, 20 Dec, 2014 at 08:00 am ServSafe Food Handler Card - CALIFORNIA, DC, TEXAS AND ALL STATES - ONLINE

Online

WORKSHOPS VIRTUAL
Creative Photography
Sat, 07 Mar, 2015 at 10:00 am Creative Photography

Westland Place Studios

WORKSHOPS PHOTOGRAPHY
FENG SHUI FOR MONEY:  Feng Shui Class on Manifesting the Law of Attraction Series, 90 min. Pre-Recorded Video Class
Wed, 01 Apr, 2015 at 06:00 pm FENG SHUI FOR MONEY: Feng Shui Class on Manifesting the Law of Attraction Series, 90 min. Pre-Recorded Video Class

Feng Shui Training Center

WORKSHOPS MEDITATION
Family Meet & Greet Dinner
Wed, 06 May, 2015 at 05:00 pm Family Meet & Greet Dinner

The Bay View Restaurant

WORKSHOPS
Surry Hills Dining Tour
Thu, 10 Sep, 2015 at 06:30 pm Surry Hills Dining Tour

Four Pillars Laboratory - Eileen's Bar

WORKSHOPS FOOD-DRINKS
Second Saturday Divorce Workshop, San Diego North County
Sat, 12 Sep, 2015 at 08:30 am Second Saturday Divorce Workshop, San Diego North County

MiraCosta College San Elijo Campus

WORKSHOPS
Friction Fire Lighting in the Woods
Sun, 24 Apr, 2016 at 10:00 am Friction Fire Lighting in the Woods

Axe & Paddle Bushcraft

WORKSHOPS ART
Excel Pivot Tables in 45 Minutes, Southampton
Mon, 23 May, 2016 at 09:00 am Excel Pivot Tables in 45 Minutes, Southampton

Building 1000, Lakeside North Harbour

WORKSHOPS
7:15 am Monday Shallow\/Deep Water Circuit (Sabrina)
Mon, 12 Sep, 2016 at 07:00 am 7:15 am Monday Shallow/Deep Water Circuit (Sabrina)

La Petite Baleen Swim School

WORKSHOPS
7:15 am Saturday Turbo Tabata (Sabrina) PLEASE READ CLASS DESCRIPTION
Sat, 17 Sep, 2016 at 07:15 am 7:15 am Saturday Turbo Tabata (Sabrina) PLEASE READ CLASS DESCRIPTION

La Petite Baleen Swim School

WORKSHOPS
Heart Safe Plymouth
Wed, 28 Sep, 2016 at 07:00 pm Heart Safe Plymouth

Plymouth City Hall - Medicine Lake Conference Room

WORKSHOPS BUSINESS
Brigham and Women's Breastfeeding Class
Wed, 05 Oct, 2016 at 05:00 pm Brigham and Women's Breastfeeding Class

Online

WORKSHOPS HEALTH-WELLNESS

What's Happening Next in Online?

Discover Online Events