Informational and instructional videos, labs, and documents for Snort 2 and Snort 3.
This introduction to Snort is a high-level overview of Snort 2, Snort 3, the underlying rule set, and Pulled Pork. If you are new to Snort, watch this video for a quick orientation before downloading, installing, or configuring Snort. All links mentioned in the video are below. You can also listen to the Talos Takes episode on Snort, which provides a quick overview of Snort rules below.
In Cisco Talos' latest roundtable, we gathered folks from every corner of Snort to discuss Snort 3. We cover the software's lifecycle, its origins and make a pitch for why you should upgrade today.
|VRT Methodology: Focusing on Protecting "Your" Network||2011|
|Inline Normalization with Snort 2.9.0||2010|
|Using Perfmon and Performance Profiling to Tune Snort Preprocessors and Rules||2009|
|Target-Based TCP Timestamp Stream Reassembly (with introduction to timestamps)||2007|
|Target-Based Fragmentation Reassembly||2005|
|HTTPS IDS Evasions Revisited||2004|
|Performance Rules Creation/VRT Rules Methodology, Snort Architecture (Preprocessors, Detection Methodology)||2003|
|Optimizing Pattern Matching for Intrusion Detection||2002|
|Performance Rules Creation Part 2, Rule Options and Techniques||2002|
|OpenAppID: Open Source Community Webinar||2015|
|OpenAppID: Development Manager Costas Kleopa, Open Source Community Webinar|
|Snort Installation and Configuration|
|Basics of Snort Rule Writing (Snort2)|
|Snort Installation, Configuration, and Basic Usage|
|How to Create Useful False Positive Reports|
|Performance Tuning Snort|
|Using the Host Attribute Table Feature in Snort|
|Open Source Community Webinar||2013|
|Snort Tuning 101||2011|
|Possible Packet Loss During Reassembly||2015|