snort Logo

snort

0
Free
Visit Website

Snort is an open source intrusion prevention system capable of real-time traffic analysis and packet logging. It uses a series of rules to define malicious network activity and generates alerts for users. It can be deployed inline to stop malicious packets and can be used as a packet sniffer, packet logger, or a full-blown network intrusion prevention system. Snort has two sets of rules: the Community Ruleset and the Snort Subscriber Ruleset. The Snort Subscriber Ruleset is developed, tested, and approved by Cisco Talos, while the Community Ruleset is developed by the Snort community and QAed by Cisco Talos. To get started with Snort, users need to download and install the source code, sign up and get an Oinkcode, and configure the rules.

FEATURES

ALTERNATIVES

A suite for man in the middle attacks, featuring sniffing of live connections, content filtering, and protocol dissection.

Simple perl script for making Modbus transactions from the command line.

A library for integrating communication channels with the Cobalt Strike External C2 server.

Mass IP port scanner for Internet-scale scanning with high speed and flexibility.

A bash script for scanning a target network for HTTP resources through XXE

A tool for extracting files from network traffic based on file signatures with support for various file formats and scalable search algorithm.

mitmproxy is an interactive, SSL/TLS-capable intercepting proxy with a console interface for HTTP/1, HTTP/2, and WebSockets.

Tcpreplay is a suite of Open Source utilities for editing and replaying captured network traffic.