These accounts existed only for container UID mapping and filesystem ownership, but user.present omitted shell:, so Salt fell through to the platform useradd default and every one of them got /bin/bash. Pin them to /sbin/nologin so none can be used as an interactive login or `su -` target. socore keeps /bin/bash: `su socore -c '/usr/sbin/so-repo-sync'` in soup and so-kernel-upgrade execs the account's passwd shell, and operator docs tell users to su to socore. soqemussh keeps /bin/bash as an SSH login account. elastic-agent, elastic-agent-pr and kafka are included alongside the accounts named in the issue, being the same class with the same unset shell, so the default is uniform. Cron is unaffected: cronie runs jobs via the crontab SHELL (default /bin/sh), not the passwd shell. suricata is the only account changed here that owns a crontab, and somon has shipped as nologin with a working cron job already. The zeek `runuser -l zeek` calls all run inside so-zeek via docker.run/exec, so they resolve the shell from the image, not the host. Verified on a 3.4.0 managersearch + sensor grid: highstate converges with the shell as the only change and no failures, is idempotent on a second run, all containers stay up, SOC still issues a Kratos login flow, and the suricata surilogcompress cron job runs post-change ((suricata) CMD/CMDEND in /var/log/cron) while `su - suricata` is now refused. Closes #16256
Security Onion
Security Onion is a free and open Linux distribution for threat hunting, enterprise security monitoring, and log management. It includes a comprehensive suite of tools designed to work together to provide visibility into your network and host activity.
✨ Features
Security Onion includes everything you need to monitor your network and host systems:
- Security Onion Console (SOC): A unified web interface for analyzing security events and managing your grid.
- Elastic Stack: Powerful search backed by Elasticsearch.
- Intrusion Detection: Network-based IDS with Suricata and host-based monitoring with Elastic Fleet.
- Network Metadata: Detailed network metadata generated by Zeek or Suricata.
- Full Packet Capture: Retain and analyze raw network traffic with Suricata PCAP.
⭐ Security Onion Pro
For organizations and enterprises requiring advanced capabilities, Security Onion Pro offers additional features designed for scale and efficiency:
- Onion AI: Leverage powerful AI-driven insights to accelerate your analysis and investigations.
- Enterprise Features: Enhanced tools and integrations tailored for enterprise-grade security operations.
For more information, visit the Security Onion Pro page.
☁️ Cloud Deployment
Security Onion is available and ready to deploy in the AWS, Azure, and Google Cloud (GCP) marketplaces.
🚀 Getting Started
| Goal | Resource |
|---|---|
| Download | Security Onion ISO |
| Requirements | Hardware Guide |
| Install | Installation Instructions |
| What's New | Release Notes |
📖 Documentation & Support
For more detailed information, please visit our Documentation.
- FAQ: Frequently Asked Questions
- Community: Discussions & Support
- Training: Official Training
🤝 Contributing
We welcome contributions! Please see our CONTRIBUTING.md for guidelines on how to get involved.
🛡️ License
Security Onion is licensed under the terms of the license found in the LICENSE file.
Built with 🧅 by Security Onion Solutions.