# Major Announcement: WinSuricata v3.0 Shifts to a Modular Architecture

**URL:** <https://forum.suricata.io/t/major-announcement-winsuricata-v3-0-shifts-to-a-modular-architecture/6445>\
**Category:** Community Announcements\
**Created:** [August 26, 2026, 10:57pm UTC](https://forum.suricata.io/t/major-announcement-winsuricata-v3-0-shifts-to-a-modular-architecture/6445 "2026-08-26T22:57:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Morpheus101](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Morpheus101](https://forum.suricata.io/u/Morpheus101)\
**Post date:** [August 26, 2026, 10:57pm UTC](https://forum.suricata.io/t/major-announcement-winsuricata-v3-0-shifts-to-a-modular-architecture/6445/1 "2026-08-26T22:57:57Z")

</div>

We are excited to officially announce the release of the **WinIDS v3.0 Deployment Framework**.

To provide greater flexibility, lighter system footprints, and tailored deployment models, we have retired the previous monolithic/standalone installer model. Moving forward, WinSuricata v3.0 uses a **modular, decoupled architecture**.

**What Changed?**

Rather than forcing a full console and database stack onto every endpoint, WinIDS v3.0 splits core functionality into a base engine and optional console add-ons:

- **Core Engine (Base Deployment):**  **WinSuricata Sensor — Engine Edition**

- **Console Add-On Option 1:**  **EveBox Console — SQLite Edition**

- **Console Add-On Option 2:**  **EveBox + OpenSearch + OpenSSL Console — Enterprise Edition**

**Deployment Flow & Prerequisites**

1. **Deploy Core First:** Always install the **WinSuricata Engine Edition** base package first to establish your network sensor and `eve.json` log generation.

2. **Attach an Add-On (Optional):** If you require a local GUI or search engine, execute either the **SQLite** or **OpenSearch** Add-On installer against your existing WinIDS installation.

**Documentation & Support**

Updated deployment guides and technical documentation are included inside each archive package. For community assistance, bug reports, and rule updater discussions, visit [WinSnort.com](https://winsnort.com/).

---

<div class="post-metadata">

**Author:** ![lukashino](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/lukashino/32/1150_2.png) [@lukashino](https://forum.suricata.io/u/lukashino)\
**Post date:** [August 28, 2026, 12:00pm UTC](https://forum.suricata.io/t/major-announcement-winsuricata-v3-0-shifts-to-a-modular-architecture/6445/2 "2026-08-28T12:00:42Z")

</div>

Available WinIDS materials make no mention of Suricata.

Additionally, the latest post mention [WinIDS 4.1](https://www.winsnort.com/announcement/50-official-release-winids-automated-deployment-framework-v41/) not 2.6/3.0 as published here on the forum recently.

I vote to flag this and future posts as a spam.

---

<div class="post-metadata">

**Author:** ![Morpheus101](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Morpheus101](https://forum.suricata.io/u/Morpheus101)\
**Post date:** [August 28, 2026, 12:58pm UTC](https://forum.suricata.io/t/major-announcement-winsuricata-v3-0-shifts-to-a-modular-architecture/6445/3 "2026-08-28T12:58:45Z")

</div>

> [@Major Announcement: WinSuricata v3.0 Shifts to a Modular Architecture](https://forum.suricata.io/t/major-announcement-winsuricata-v3-0-shifts-to-a-modular-architecture/6445/2):
>
> Available WinIDS materials make no mention of Suricata. Additionally, the latest post mention [WinIDS 4.1](https://www.winsnort.com/announcement/50-official-release-winids-automated-deployment-framework-v41/) not 2.6/3.0 as published here on the forum recently. I vote to flag this and future posts as a spam.

To clear up the confusion: WinIDS 4.1 is for WinSnort, which is why it doesn’t mention Suricata (that’s handled separately under WinSuricata). As for the visibility, if Suricata wants to sponsor a more prominent placement, we can discuss terms. Definitely not spam—just separate packages.

Forums: [Auto-Installer WinIDS Deployments: WinSuricata - The Winsnort Community](https://www.winsnort.com/forum/61-auto-installer-winids-deployments-winsuricata/)

Dowlnloads: [Auto-Installers for WinSuricata Deployments - The Winsnort Community](https://www.winsnort.com/files/category/5-auto-installers-for-winsuricata-deployments/)

---

<div class="post-metadata">

**Author:** ![lukashino](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/lukashino/32/1150_2.png) [@lukashino](https://forum.suricata.io/u/lukashino)\
**Post date:** [August 28, 2026, 2:00pm UTC](https://forum.suricata.io/t/major-announcement-winsuricata-v3-0-shifts-to-a-modular-architecture/6445/4 "2026-08-28T14:00:23Z")

</div>

Ok, thank you for the clarification.

---

<div class="post-metadata">

**Author:** ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)\
**Post date:** [August 28, 2026, 2:21pm UTC](https://forum.suricata.io/t/major-announcement-winsuricata-v3-0-shifts-to-a-modular-architecture/6445/5 "2026-08-28T14:21:26Z")

</div>

I don’t consider it spam, but the number of new topics about this effort is getting too high (3 within 3 weeks). Please update one of your existing topics if there is more to report.

---

<div class="post-metadata">

**Author:** ![Morpheus101](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Morpheus101](https://forum.suricata.io/u/Morpheus101)\
**Post date:** [August 28, 2026, 3:06pm UTC](https://forum.suricata.io/t/major-announcement-winsuricata-v3-0-shifts-to-a-modular-architecture/6445/6 "2026-08-28T15:06:01Z")

</div>

Understood, thanks for letting me know! That makes complete sense and I definitely don’t want to clutter the forum feed. Going forward, I’ll update one of my existing topics whenever there’s new progress to report.

As a heads-up, I’ve pretty much reached the end of my major updates for now. The upcoming v4.0 work is still way down the road, and any smaller adjustments in the meantime will just be minor news posted directly on [WinSnort.com](http://WinSnort.com) without creating new threads here. Thanks again for clarifying how the notification tagging works!

```auto
WINSNORT.com Management…

********************Established ~ 2003**********************
* FREE Windows Intrusion Detection System (WinIDS) Tutorials *
* ~~FREE Windows Support Forums~~ *
* Visit @ https://winsnort.com *
* Snort: Open Source Network IDS - https://snort.org *
* Suricata: Open Source Network IDS - https://suricata.io *
**************************************************************

```
