Is something similar or newer than 'Playbooks' coming up on an update post Security Onion 2.4.80? #13333
Replies: 2 comments 4 replies
-
You should take a look at the following: Or TL;DR just click here: https://www.youtube.com/watch?v=oxR4q53N6OI I'm guessing even though it says 2.4.70 that it's what your after their new "Detection" feature. PS. IMO - Detection looks pretty neat. Even though I was also happy with playbooks UI (when i finally found out how to use it), but it took some real long and dinky learning curve for me to use properly :) Hopefully the new Detection solution is going to be perfect. |
Beta Was this translation helpful? Give feedback.
-
I'm new in SO too and I eared about playbook. I understood that it was able to do actions (like send an email) when an alert is created. Now, in Detections feature, I'm not able to find something similar. You told something about "alert detection feature". Was it a functionality similar to that I say. If so, Is it possible thand the new Detections Feature has less features than old Playbook? I'll thank so much your opinion because I'm trying to learn SO and it's being very hard to me because of outdated information in the net. Thanks! |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I was using Security Onion Version 2.4.60 for my labs of preparing Cloud SOC on AWS. I was making a report for a playbook-based detection experiment for some days at the end of last month (June 2024). Around that period, I was notified that a new version of Security Onion had been released a version 2.4.80.
I already had a snapshot of version 2.4.60, so I went ahead and updated it. However, I was surprised to see that the Tools → Playbook section has been removed!
I went through the documentation at #https://blog.securityonion.net/2024/06/security-onion-2480-now-available.html to see that playbooks has been removed in preparation for the new 'detection' module. Can someone clarify more on this, whether my knowledge and experiments would be useful in future now that 'Playbooks' have been removed?
I found this alert detection feature very useful always. Any news of it coming back, or what shall we need to be prepared of to upskill on our 'detection-engineering' skills?
Beta Was this translation helpful? Give feedback.
All reactions