/etc/snort
Overview of /etc/snort
/etc/snortvar HOME_NET 192.168.1.0/24 var EXTERNAL_NET any include $RULE_PATH/local.rules include $RULE_PATH/community.rules include $RULE_PATH/snort.rules
config classification: attempted-admin,Attempted Administrator Privilege Gain,1 config classification: attempted-user,Attempted User Privilege Gain,2
config reference: bugtraq https://www.securityfocus.com/bid/ config reference: cve https://cve.mitre.org/cgi-bin/cvename.cgi?name=
1000001 || ICMP PING NMAP || cve,CAN-1999-0524 || url,www.securityfocus.com/bid/277
threshold gen_id 1, sig_id 1000001, type threshold, track by_src, count 5, seconds 60
DEBIAN_SNORT_STARTUP="yes" INTERFACE="eth0"
Example Directory Structure
Best Practices
Last updated