Audience
IT teams searching for a network detection and prevention solution
About Snort
Snort is the foremost Open Source Intrusion Prevention System (IPS) in the world. Snort IPS uses a series of rules that help define malicious network activity and uses those rules to find packets that match against them and generates alerts for users. Snort can be deployed inline to stop these packets, as well. Snort has three primary uses: As a packet sniffer like tcpdump, as a packet logger — which is useful for network traffic debugging, or it can be used as a full-blown network intrusion prevention system. Snort can be downloaded and configured for personal and business use alike. Once downloaded and configured, Snort rules are distributed in two sets: The “Community Ruleset” and the “Snort Subscriber Ruleset.” The Snort Subscriber Ruleset is developed, tested, and approved by Cisco Talos. Subscribers to the Snort Subscriber Ruleset will receive the ruleset in real-time as they are released to Cisco customers.
Integrations
Company Information
Product Details
Snort Frequently Asked Questions
Snort Product Features
Snort Additional Categories
Snort Verified User Reviews
Write a Review-
Probability You Would Recommend?1 2 3 4 5 6 7 8 9 10
"Snort it whoops the llamas butt" Posted 2023-11-20
Pros: Free for any platform not just the web.
Has multiple different filter lists to learn about and choose from based off of your needs.Cons: A little bit of a pain to set up on windows if you don't know how to use command prompt.
Overall: Snort has been around for ages and is a IDS that I trust when I had a IPCop firewall I had snort enabled with my Oink code, when I ran Pfsense I had snort enabled as well.
Read More...
You don't need those firewall OSes to run snort but it helps overall to have a strong firewall ruleset to backup the IDS filters that snort has.
- Previous
- You're on page 1
- Next