Major Announcement: WinSuricata v3.0 Shifts to a Modular Architecture

We are excited to officially announce the release of the WinIDS v3.0 Deployment Framework.

To provide greater flexibility, lighter system footprints, and tailored deployment models, we have retired the previous monolithic/standalone installer model. Moving forward, WinSuricata v3.0 uses a modular, decoupled architecture.

What Changed?

Rather than forcing a full console and database stack onto every endpoint, WinIDS v3.0 splits core functionality into a base engine and optional console add-ons:

  • Core Engine (Base Deployment): WinSuricata Sensor — Engine Edition

    • Deploys a lean, high-performance, headless IDS/IPS sensor node running pure Suricata.

    • Zero local web console or database footprint.

    • Captures packets via Npcap, manages rules automatically, and outputs standard eve.json telemetry.

  • Console Add-On Option 1: EveBox Console — SQLite Edition

    • Designed for lightweight, single-node visibility.

    • Ingests local eve.json streams into an embedded SQLite database engine.

    • Exposes the EveBox Web UI on port 5636 with minimal overhead.

  • Console Add-On Option 2: EveBox + OpenSearch + OpenSSL Console — Enterprise Edition

    • Designed for high-volume event indexing, analytics, and enterprise multi-node environments.

    • Integrates OpenSearch as the analytics backend, automated OpenSSL PKI for TLS encryption, and secure HTTPS pipelines.

Deployment Flow & Prerequisites

  1. Deploy Core First: Always install the WinSuricata Engine Edition base package first to establish your network sensor and eve.json log generation.

  2. Attach an Add-On (Optional): If you require a local GUI or search engine, execute either the SQLite or OpenSearch Add-On installer against your existing WinIDS installation.

Documentation & Support

Updated deployment guides and technical documentation are included inside each archive package. For community assistance, bug reports, and rule updater discussions, visit WinSnort.com.

Available WinIDS materials make no mention of Suricata.

Additionally, the latest post mention WinIDS 4.1 not 2.6/3.0 as published here on the forum recently.

I vote to flag this and future posts as a spam.

To clear up the confusion: WinIDS 4.1 is for WinSnort, which is why it doesn’t mention Suricata (that’s handled separately under WinSuricata). As for the visibility, if Suricata wants to sponsor a more prominent placement, we can discuss terms. Definitely not spam—just separate packages.

Forums: Auto-Installer WinIDS Deployments: WinSuricata - The Winsnort Community

Dowlnloads: Auto-Installers for WinSuricata Deployments - The Winsnort Community

Ok, thank you for the clarification.

I don’t consider it spam, but the number of new topics about this effort is getting too high (3 within 3 weeks). Please update one of your existing topics if there is more to report.

Understood, thanks for letting me know! That makes complete sense and I definitely don’t want to clutter the forum feed. Going forward, I’ll update one of my existing topics whenever there’s new progress to report.

As a heads-up, I’ve pretty much reached the end of my major updates for now. The upcoming v4.0 work is still way down the road, and any smaller adjustments in the meantime will just be minor news posted directly on WinSnort.com without creating new threads here. Thanks again for clarifying how the notification tagging works!

WINSNORT.com Management…

******************** Established ~ 2003 **********************
* FREE Windows Intrusion Detection System (WinIDS) Tutorials *
*            ~~ FREE Windows Support Forums ~~               *
*               Visit @ https://winsnort.com                 *
*     Snort: Open Source Network IDS - https://snort.org     *
*  Suricata: Open Source Network IDS - https://suricata.io   *
**************************************************************