snort Logo

snort

0
Free
Visit Website

Snort is an open source intrusion prevention system capable of real-time traffic analysis and packet logging. It uses a series of rules to define malicious network activity and generates alerts for users. It can be deployed inline to stop malicious packets and can be used as a packet sniffer, packet logger, or a full-blown network intrusion prevention system. Snort has two sets of rules: the Community Ruleset and the Snort Subscriber Ruleset. The Snort Subscriber Ruleset is developed, tested, and approved by Cisco Talos, while the Community Ruleset is developed by the Snort community and QAed by Cisco Talos. To get started with Snort, users need to download and install the source code, sign up and get an Oinkcode, and configure the rules.

FEATURES

ALTERNATIVES

PFQ v6.2 is a functional framework for Linux optimized for efficient packet capture/transmission and in-kernel processing.

Snort 3 is the next generation Snort IPS with enhanced features and improved cross-platform support.

Detects Kippo SSH honeypot instances externally

A specialized packet sniffer for displaying and logging HTTP traffic, designed to capture, parse, and log traffic for later analysis.

A service for better visibility on networking issues in Kubernetes clusters by detecting traffic denied by iptables.

A utility to generate malicious network traffic for security evaluation.

A network detection and response solution that uses AI and machine learning to monitor network traffic, identify malicious behavior, and connect related security events to reveal attack patterns without requiring endpoint agents.

CrowdSec is a behavior detection engine with a global IP reputation network.