The article discusses the use of the Security Onion platform for modelling cyber threats and evaluating the effectiveness of intrusion detection systems (IDS). Experiments have been conducted to simulate various types of attacks, such as SYN flood, brute-force, DNS flood, and DNS tunnelling, using Kali Linux tools. The results of attack detection using Suricata IDS are analysed and the data are visualised in Kibana. The results of the study demonstrate the effectiveness of using Security Onion as a comprehensive solution for monitoring, analysing, and responding to cyber threats.