Skip to content
Discussion options

You must be logged in to vote

We typically don't call Security Onion an XDR solution, but a solution for ESM, or Enterprise Security Monitoring. With regard to OpenEDR, I have not tried it. It appears that it only supports installation for Windows endpoints. If speaking to EDR and a more response-oriented tool, you may have a look at Velociraptor, which supports Linux, MacOS, and Windows endpoints. While it is not officially supported, you can check out the integration project here: https://github.com/weslambert/securityonion-velociraptor. Otherwise we have other endpoint-focused tools like Wazuh, Elastic Beats, and Osquery that already natively integrate with Security Onion.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet
2 participants