Snort

From SecurityTools
Revision as of 02:49, 2 October 2023 by RagManX (talk | contribs) (Added Screenshots and Similar Tools section, plus one additional More Information link)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Description

Snort is the foremost open-source Intrusion Prevention System (IPS) in the world. It is an intrusion prevention system capable of real-time traffic analysis and packet logging. Snort is freely downloadable from the Snort home page, with the difference between the free and commercial versions being the rulesets used by the tool. Ruleset annual pricing is $29.99 for individuals or $399 per sensor for businesses. You can run a Snort sensor on the community ruleset, but you get the latest updates 30 days after paid subscribers do.

Tool Type

More Information

Sample Use/Screenshots

  • Snort man page
    Snort man page
    Here is the man page's opening, showing just the available options for running Snort
  • A sample of /var/log/snort/snort.alert.fast output from a recently started Snort instance
  • Snort bad traffic default rules
    Snort bad traffic rules
    A sample of Snort rules, this from the bad-traffic default rules

Similar Tools