Snort - the de facto standard for intrusion detection/prevention

What is Snort?
SNORT® is an open source network intrusion prevention and detection system utilizing a rule-driven language, which combines the benefits of signature, protocol and anomaly based inspection methods. With millions of downloads to date, Snort is the most widely deployed intrusion detection and prevention technology worldwide and has become the de facto standard for the industry.


Get the latest Snort release Visit the Snort store Get certified with Snort Training!
2008 Snort Scholarship
Snort ScholarshipThe application period for the 2008 Snort Scholarships is now closed.
Rules from the Source
VRT Certified Rules provide up to date coverage for the latest network threats.
Snort 2.8.1
Snort 2.8.1 is now available.
Project Spotlight
Snort Users Webcast Series
In this one-hour, recorded webcast, Ed Mendez, Director of Instructional Design and Development, discusses the basic steps necessary to install, configure and use Snort. The session covers:
Planning a deployment - Preparing for the install - Software requirements - Installing Snort - Basic Snort operation - Tuning strategies
View the webcast | download the slides
Basic Analysis and Security EngineBASE: Basic Analysis and Security Engine
BASE is the Basic Analysis and Security Engine. It is based on the code from the Analysis Console for Intrusion Databases (ACID) project. This application provides a web front-end to query and analyze the alerts coming from a SNORT sensor.

The latest BASE 1.3.6 (Louise) release is available for download. Check out the project here.
Document Spotlight
Sourcefire VRT White PaperSourcefire Vulnerability Research Team (VRT) White Paper
White Paper covering the capabilities and processes followed by the Sourcefire VRT in writing rules.
Get it here.