Overview
Suricata is the open-source network threat detection engine developed by the Open Information Security Foundation (OISF). This AMI from AdvanceCo packages Suricata 8 on Ubuntu 24.04 LTS so you can start inspecting AWS network traffic without building and maintaining the sensor yourself.
What is included
- Suricata 8.0.x from the official OISF package repository, pinned to the 8.0 release series
- Ubuntu 24.04 LTS with all available security updates applied when the image is built
- suricata-update for downloading and refreshing rule sets such as ET Open
- A systemd service unit for running Suricata as a service
- A hardened image: root password locked, and no SSH keys, shell history or cloud-init state carried over from the build
How you can use it
- Passive IDS with Amazon VPC Traffic Mirroring: Suricata decodes VXLAN-encapsulated mirror traffic, so one sensor can inspect traffic from other instances without changing them.
- Inline IPS: run Suricata in AF-PACKET inline mode on an instance that routes traffic, and drop traffic that matches your rules.
- Network security monitoring: EVE JSON logs record alerts plus protocol metadata for HTTP, DNS, TLS, QUIC, SMB, SSH and more, ready to ship to Amazon CloudWatch Logs, Amazon OpenSearch Service or a third-party SIEM.
- Compliance evidence: network intrusion detection is a common control in frameworks such as PCI DSS, and Suricata's logs can support the evidence you provide for it.
What Suricata 8 brings
- A multi-threaded engine that scales with instance vCPUs
- TLS and QUIC handshake visibility, including SNI and JA3/JA4 fingerprints, without decrypting traffic
- New and expanded protocol parsers, including LDAP
Maintenance and support AdvanceCo rebuilds this AMI with current Ubuntu security patches and the latest Suricata 8.0 point release, and publishes updates as new versions of this listing. Included support is by email during US business hours from our US-based team. Paid support with Slack, phone and response-time commitments is available on request.
Getting started Launch the AMI and connect over SSH as the ubuntu user. Set your capture interface in /etc/suricata/suricata.yaml, run suricata-update to load rules, then restart the suricata service. For Traffic Mirroring, allow UDP 4789 from your mirror sources in the instance security group.
Highlights
- Suricata 8 on Ubuntu 24.04 LTS: OISF packages pinned to the 8.0 series, with all Ubuntu security updates applied and the image hardened before release.
- Built for AWS traffic inspection: VXLAN decoding lets one sensor inspect traffic from Amazon VPC Traffic Mirroring, or run it inline in AF-PACKET IPS mode.
- SIEM-ready EVE JSON logging: alerts and protocol metadata for HTTP, DNS, TLS, QUIC, SMB and more, with US-based support from AdvanceCo.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
- Monthly subscription
- $625.00/month
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Suricata 8.0.7 from the OISF 8.0 package repository on Ubuntu 24.04 LTS, with all Ubuntu security updates available on 2026-10-04 applied. Built by AdvanceCo's automated image pipeline: the image is hardened (root password locked, no SSH keys, shell history or cloud-init state from the build) and tested before release.
Additional details
Usage instructions
Connect over SSH as the ubuntu user. Set your capture interface in /etc/suricata/suricata.yaml, run 'sudo suricata-update' to load rules, then 'sudo systemctl restart suricata'. For VPC Traffic Mirroring, allow UDP 4789 from your mirror sources. The recommended security group allows SSH and VXLAN only from 10.0.0.0/8; widen it if needed. Support: secproductsupport@advancecoinc.com
Resources
Vendor resources
Support
Vendor support
Included support: email support from AdvanceCo's US-based engineering team during US business hours at secproductsupport@advancecoinc.com . Paid support options, including Slack, phone and response-time commitments, are available on request. More information:
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.