---
title: SELKS 5 - The Sorceress
description: SELKS5 - The Sorceress
---

[Stamus-Networks-Blog ](https://www.stamus-networks.com/blog)

# [SELKS 5 - The Sorceress](https://www.stamus-networks.com/blog/2019/04/16/selks5-the-sorceress)

 Written by [Peter Manev](https://www.stamus-networks.com/blog/author/peter-manev) | Apr 16, 2019 1:46:23 PM

SELKS 5 is out! Thank you to the whole community for your help and feedback! Thank you to all the great Open Source projects and tools mentioned below for making it possible to showcase Suricata with this new release.

All components have been upgraded in this release to the latest version available but this is not the main improvement. SELKS is now able of doing Full Packet Capture thanks to Suricata and Moloch and benefit from an upgraded Scirius CE adding a new threat hunting interface.

 

<https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2019-04-16-14-19-27.png?hsLang=en> Alert metadata in Scirius Hunting interface

 

Moloch addition allows the user to investigate and explore captured data via the Moloch viewer that provide an intuitive interface. The new Scirius threat hunting interface proposes a drill-down approach that allow to quickly find relevant alerts in a haystack and start investigation by what matter.

Features, fixes and major improvements:

- The whole stack has been upgraded 
    - Over 21 new dashboards
    - Hundreds of visualizations
    - New Threat Hunting interface
    - Full Packet Capture possibility
- [Elasticsearch 6.7.1](https://www.elastic.co/products/elasticsearch)
- [Logstash 6.7.1](https://www.elastic.co/products/logstash)
- [Kibana 6.7.1](https://www.elastic.co/products/kibana)
- [Moloch 1.8.0](https://molo.ch/)  -  The new SELKS makes use of Moloch and Moloch viewer to parse and view the full packet capture done by Suricata. Moloch comes with an arsenal of tools and features on its own like: 
    - [CyberChef](https://gchq.github.io/CyberChef/)
    - Extremely flexible and easy to use interface for FPC drill down, filtering, search and pcap export
- Scirius 3.2.0 CE 
    - - Threat Hunting based on Suricata's alerts metadata
          - Administration, ruleset and threat hunting management
          - Any field and action are selectable and searchable
          - Order and set up your own threat hunting dashboard in seconds with drag and drop functionality

 

<https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2019-04-16-14-18-07.png?hsLang=en> TLS Server Name Identification

 

 

<https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2019-04-16-14-17-25.png?hsLang=en> HTTP UserAgent selection

 

 

 

<https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2019-04-16-14-16-48.png?hsLang=en> Easily select and filter on any metadata

 

 

- [Suricata](https://suricata-ids.org/)  - latest git edition anytime available.
- SELKS scripts upgrade 
    - available now system wide in "/usr/bin"
    - Full packet Capture retention policy - thanks [Joren0494](https://github.com/Jeroen0494) !
    - selks-health-check_stamus  - SELKS health check script
- Debian - always thankful !
- [EveBox](https://evebox.org/) - always the latest and very thankful for your support and extremely fast bug fixing and feature addition

[More  screenshots of SELKS 5 release ](https://www.stamus-networks.com/2018/10/26/selks5-beta/?hsLang=en)

SELKS is both Live and installable Network Security Management ISO based on Debian implementing and focusing on a complete and ready to use Suricata IDS/IPS ecosystem with its own graphic rule manager. Stamus Networks is a proud member of the Open Source community and SELKS is released under GPLv3 license.

#### Download

To download SELKS 5, pick one of the two flavors:

##### SELKS with desktop

- HTTP: [SELKS-5.0-desktop.iso](https://www.stamus-networks.com/sn-dl/selks/60c52286df9d1d250efac3f24644bd5b59bf5728d2c50bd722d8e4c9e8ce2089/SELKS-5.0-desktop.iso?hsLang=en)
- Sha256sum: 60c52286df9d1d250efac3f24644bd5b59bf5728d2c50bd722d8e4c9e8ce2089

##### SELKS without desktop

- HTTP: [SELKS-5.0-nodesktop.iso](https://www.stamus-networks.com/sn-dl/selks/e571611b374462f67ed7588a1b9f5e81c7fcac50f953df45a278ff238914ade8/SELKS-5.0-nodesktop.iso?hsLang=en)
- Sha256sum: e571611b374462f67ed7588a1b9f5e81c7fcac50f953df45a278ff238914ade8

#### Usage

You can find the first time set up instructions on our [SELKS 5.0 wiki page](https://github.com/StamusNetworks/SELKS/wiki/First-time-setup).

SELKS 4 user can upgrade their running systems using the following [Upgrade instructions](https://github.com/StamusNetworks/SELKS/wiki/SELKS-4.0-to-SELKS-5.0-upgrades).

#### Feedback is welcome

Any feedback as always is greatly appreciated! :)

Give us feedback and get help on:

- Freenode IRC on the #SELKS channel
- [Google Mailing list](http://groups.google.com/d/forum/selks)

While this test upgrade/installation has been verified and tested please make sure you try it in your test/QA set up first.

Thank you!

 

[View full post](https://www.stamus-networks.com/blog/2019/04/16/selks5-the-sorceress)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Peter Manev"
  },
  "dateModified" : "2023-01-19T12:28:57.270Z",
  "datePublished" : "2019-04-16T13:46:23Z",
  "headline" : "SELKS 5 - The Sorceress",
  "image" : {
    "@type" : "ImageObject",
    "height" : 1125,
    "url" : "https://cdn2.hubspot.net/hubfs/6344338/SELKS5_Featured_Image.png",
    "width" : 1999
  },
  "mainEntityOfPage" : "https://www.stamus-networks.com/blog/2019/04/16/selks5-the-sorceress",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/6344338/stamus_logo_blue_cropped-1.png",
      "width" : 186.66667
    },
    "name" : "Stamus Networks Blog"
  }
}
```