Snort Official Documentation

The official documentation produced by the Snort team at Sourcefire

Title Author
Snort Users ManualPDF Small Snort Team
Snort FAQ Snort Team
The Snort Manual (HTML) Snort Team



Snort Setup Guides

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author. Authors who want comments and feedback may be emailed by clicking on their names below.

If you have a document you’d like to contribute to the Snort community contact us at snort-team@sourcefire.com.

Title Author
Snort 2.9.2.0 on Ubuntu 10.04 LTS
David Gullett, Symmetrix Technologies
Snort 2.9.1.2 on Mac OS X
Christoph Murauer
Snort 2.9.1.2 on Debian 6.0
Jason Weir
Snort 2.9.1 with Barnyard2 on RHEL 6.1 x64
Randal Rioux, Procyonlabs
Snort 2.9.1 on CentOS 5.6 Nick Moore, Sourcefire
Snort 2.9.0.x with PF_RING Inline deployment Metaflows Google Group
Snort 2.9.0.5 on OpenSuSE 11.4
Bill Parker
Snort on Amazon EC2PDF Small Etay Nir, Sourcefire



Snort Deployment Guides

The following deployment guides have been contributed by members of the Snort Community for your use. If you have a document you’d like to contribute to the Snort community contact us at snort-team@sourcefire.com.

Title Author
Comparison of Popular Snort GUIsPDF Small James Lay
100Mb IDS Tapping Diagram with 100bt span portPDF Small Jeff Nathan
100Mb IDS Tapping Diagram with 1000bt span portPDF Small Jeff Nathan
Gig IDS Tapping Diagram with Load BalancersPDF Small Jeff Nathan
Requirements for Enterprise-Wide Scaling Intrusion Detection ProductsPDF Small Detmar Liesen



Snort Related Whitepapers

The following Whitepapers have been written by Sourcefire employees and may help with your Snort deployment. For further information on these papers, please email snort-team@sourcefire.com

Title Author
Improving your Custom Snort RulesPDF Small Leon Ward
Inline Normalization using Snort 2.9.0PDF Small Russ Combs
Using Perfmon and Performance Profiling to Tune Snort Preprocessors and RulesPDF Small Steven Sturges
VRT Rule Writing MethodologyPDF Small Sourcefire’s VRT
VRT Report on the DCE/RPC vulnerability in MS08-067PDF Small Sourcefire’s VRT
VRT Report on Dan Kaminsky’s DNS VulnerabilityPDF Small Sourcefire’s VRT
Performance Rules Creation Part 1PDF Small Matt Olney, Sourcefire’s VRT
Performance Rules Creation Part 2PDF Small Matt Olney, Sourcefire’s VRT
HTTP Evasions RevisitedPDF Small Daniel Roelker
Target Based Fragmentation ReassemblyPDF Small Judy Novak
Target-based TCP Timestamp Technical StudyPDF Small Judy Novak & Steve Sturges
Target-based Stream Reassembly and Stream5 Technical StudyPDF Small Judy Novak & Steve Sturges
Snort’s original concept paper Martin Roesch




Bookmark and Share