---
title: "SELKS 7: An Introduction"
description: Stamus Networks announces the release of SELKS 7, the free, open-source, turn-key Suricata network intrusion detection/protection system (IDS/IPS)
image: https://www.stamus-networks.com/hubfs/Dallon_Blog_Images/SELKS_Intro_Blog_2022-04-29/SELKS7-Introduction.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# SELKS 7: An Introduction

 by [Alexander Nedelchev](https://www.stamus-networks.com/blog/author/alexander-nedelchev) | May 03, 2022 | [SELKS](https://www.stamus-networks.com/blog/tag/selks), [Open Source](https://www.stamus-networks.com/blog/tag/open-source), [Suricata](https://www.stamus-networks.com/blog/tag/suricata), [Stamus Labs](https://www.stamus-networks.com/blog/tag/stamus-labs)

![](https://www.stamus-networks.com/hubfs/Dallon_Blog_Images/SELKS_Intro_Blog_2022-04-29/SELKS7-Introduction.jpg)

In this series, you will get an overview of the SELKS 7 platform, the new updates and functionality included in the recent update, as well as deployment options and practical applications. If you are already familiar with the SELKS IDS/NSM system, skip ahead to [SELKS 7: Updated Capabilities](https://www.stamus-networks.com/blog/selks-7-newly-updated-capabilities?hsLang=en) to read about all the new features or [*SELKS 7: Deployment and Application*](https://www.stamus-networks.com/blog/selks-7-deployment-and-application?hsLang=en) to learn about the practical uses and implementations possible with SELKS 7.

## **What is SELKS 7?**

Stamus Networks is pleased to announce the release of SELKS 7, the latest iteration of the free, open-source, and turn-key Suricata network intrusion detection/protection system (IDS/IPS), network security monitoring (NSM), and threat hunting implementation. Released under the GPLv3 license, the SELKS 7 system is the perfect solution whether it’s for small to medium sized organizations, the home network defender looking for a capable and effective IDS and NSM system, or security practitioners looking to experiment with Suricata.

SELKS 7 is built on eight key components:

- [Suricata](https://suricata.io/) - Ready to use Suricata
- [Elasticsearch](https://www.elastic.co/products/elasticsearch) - Search engine
- [Logstash](https://www.elastic.co/products/logstash) - Log injection
- [Kibana](https://www.elastic.co/products/kibana) - Custom dashboards and event exploration
- [Scirius CE](https://github.com/StamusNetworks/scirius) - Suricata ruleset management and Suricata threat hunting interface

Additionally, SELKS 7 utilizes functionality from[Arkime](https://arkime.com/),[Evebox](https://evebox.org/), and[CyberChef](https://gchq.github.io/CyberChef/), although those components were included after the “SELKS” acronym was established.

![Traffic filters through Suricata into SELKS](https://www.stamus-networks.com/hs-fs/hubfs/Dallon_Blog_Images/SELKS_Intro_Blog_2022-04-29/Suricata%20image.png?width=1600&name=Suricata%20image.png)

## **Why are we excited about SELKS 7?**

SELKS 7 introduces an architectural overhaul which offers numerous new possibilities. Now that the system is based on Docker, it can run on Linux or Microsoft Windows without the overhead of a virtual machine. This makes SELKS 7 faster to deploy and more flexible than it was when running off a virtual machine in previous iterations. For example, you can now[download and launch the entire instance in less than 2 minutes](https://www.stamus-networks.com/blog/complete-suricata-network-security-platform-in-2-minutes?hsLang=en).

One of the exciting benefits of the new architecture is the pcap ingest feature. You can now replay pcap files simply by running a script and you can see the result in all the integrated interfaces. Additionally, different files can be ingested and differentiated within those interfaces so you can study multiple cases simultaneously.

With SELKS 7, it’s unnecessary to experiment and test different software versions. You can now easily pick and choose which specific software component version to use with simple command line flags. These new features make SELKS 7 a valuable platform for learning and training, although the possibilities don’t stop there. With new hunting queries, a greater depth of visualization, and an intuitive dashboard, SELKS 7 offers multiple entry points for the discovery and analysis of network traffic.

**SELKS 7: A totally free, open-source, Suricata-based powerhouse IDS/NSM**

The features listed here are only the tip of the iceberg when it comes to the new updates included in SELKS 7. With these updated capabilities, there are now new features to assist in your network hunting including new dashboards and reporting abilities, integrations, the inclusion of Docker, rulesets and threat intel management, and monitoring. All of these features work together to provide new practical applications that enable the cyber defenders, whether in small to medium businesses or on their home network, to keep their networks protected against any potential threat.

Read more about the new SELKS 7 updates here or[download the system for free](https://www.stamus-networks.com/selks?hsLang=en) today.

 

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-7-an-introduction%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-7-an-introduction%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-7-an-introduction%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-7-an-introduction%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-7-an-introduction%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-7-an-introduction%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Alexander Nedelchev](https://www.stamus-networks.com/hubfs/Stamus%202020/Images/icon-user.png)

#### Alexander Nedelchev

 Alexander is a Cyber ​​Security Specialist at Stamus Networks. He graduated with a university degree in Network Technologies and has 15 years of experience in IT. Of which - 5 years in particular in the field of Cybersecurity, QA and DevOps. Alex also has hands-on and senior-level experience with Sysadmin and Datacenter installations. He actively participates in the development of SELKS and Stamus Security Platform - the commercial network detection and response (NDR) solution from Stamus Networks. Alex resides in Sofia, Bulgaria.

[**](https://www.linkedin.com/in/alexander-nedelchev-9120297/) [** ](https://twitter.com/sys7em1)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![Suricata Language Server 2.0 Now Available from Stamus Networks](https://www.stamus-networks.com/hubfs/SN-SLS-2-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

### [Suricata Language Server 2.0: Major Update with Workspace Intelligence](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

We're excited to announce version 2.0 of the Suricata Language Server, featuring workspace-wide...

[![Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/hubfs/SLS-1.3-18-Dec-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

### [Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

[Suricata Language Server](https://www.stamus-networks.com/suricata-language-server?hsLang=en) 1.3.0 is now available and it surfs on the concept of magic comment...

[![](https://www.stamus-networks.com/hubfs/SLS-1.1.0-13-Nov-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode?hsLang=en)

### [Suricata Language Server 1.1.0 Reduces Installation Requirements with Docker Container Mode](https://www.stamus-networks.com/blog/suricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode?hsLang=en)

Writing and validating Suricata signatures shouldn't require wrestling with complex installation...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.