Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Command line arguments Up: Snort Overview Previous: Specifying Multiple-Instance Identifiers   Contents

Reading Pcaps

Instead of having Snort listen on an interface, you can give it a packet capture to read. Snort will read and analyze the packets as if they came off the wire. This can be useful for testing and debugging Snort.



Subsections

Steven Sturges 2008-09-17