Snort

Snort is an open-source, rule-based Network Intrusion Detection and Prevention System (NIDS/NIPS).

1. Overview

Types

2. Description

2.1 Sniffer Mode

2.2 Logger mode

2.3 IPS mode

2.4 pcap invistigation mode

2.5 Snort Rule

Example

alert udp any any -> any any (msg:"UDP detected!!!Same SRC and DEST";sameip; sid:1000001; rev:1;)

Why it Matters?