layout
This commit is contained in:
parent
8d7e90ebca
commit
213be0b541
|
@ -1,6 +1,12 @@
|
||||||
# Snort
|
# Snort
|
||||||
|
|
||||||
Comprised of __packet decoder__, __pre processor__, __detection engine__, __logging and alerting__, __output and plugins__
|
Snort is comprised of multiple modules to process network packets.
|
||||||
|
|
||||||
|
* __packet decoder__
|
||||||
|
* __pre processor__
|
||||||
|
* __detection engine__
|
||||||
|
* __logging and alerting__
|
||||||
|
* __output and plugins__
|
||||||
|
|
||||||
## Data Aquisition Modules
|
## Data Aquisition Modules
|
||||||
|
|
||||||
|
@ -21,7 +27,7 @@ snort -c <config> -T
|
||||||
|
|
||||||
### Sniffing
|
### Sniffing
|
||||||
| Parameter | Description |
|
| Parameter | Description |
|
||||||
+-----------+-------------+
|
|-----------|-------------|
|
||||||
| -v | Verbose. Display the TCP/IP output in the console.|
|
| -v | Verbose. Display the TCP/IP output in the console.|
|
||||||
| -d | Display the packet data (payload).|
|
| -d | Display the packet data (payload).|
|
||||||
| -e | Display the link-layer (TCP/IP/UDP/ICMP) headers. |
|
| -e | Display the link-layer (TCP/IP/UDP/ICMP) headers. |
|
||||||
|
@ -80,7 +86,9 @@ snort -c /etc/snort/rules/local.rules -A full
|
||||||
* IDS -> `alert`
|
* IDS -> `alert`
|
||||||
* IPS -> `reject`
|
* IPS -> `reject`
|
||||||
|
|
||||||
`<action> <protocol> <ip.src> <src.port> <> <ip.dst> <dst.port>(msg: "<msg>; <reference>; <ruleID>;<revision info>`
|
```sh
|
||||||
|
<action> <protocol> <ip.src> <src.port> <> <ip.dst> <dst.port>(msg: "<msg>; <reference>; <ruleID>;<revision info>
|
||||||
|
```
|
||||||
|
|
||||||
* Actions
|
* Actions
|
||||||
* `alert`
|
* `alert`
|
||||||
|
|
Loading…
Reference in New Issue