Snort Rules Options
By Creigh Long
CS457: Honeypot Project
Last Updated: 4/26/06
- Official Snort rules
- subscription based - current rules, highest quality: too expensive
- registration based - 5-day-old subscription ruleset: recommended
- unregistered - only updated with each major release of Snort: stale
- community - sumbitted by members of the community and minimally tested
- Bleeding-Edge Snort rules
- volunteer run
- free Snort signature development
- released quickly
- organized into rulesets
- Bleeding
Snort Windows Ruleset Manager
- works with Oinkmaster (how to)
- Write your own rules
- Writing
Snort Rules: How To write Snort rules and keep your sanity
Other Related Rule/Ruleset Projects and Sites
- Oinkmaster (how to)
- keeps snort rules current
- sets up a cron job to update your rulesets whenever your ruleset
repository (official, bleeding, etc) is updated
- update current ruleset with your modifications from previous rulesets
- Snort IDS Policy
Manager For Windows 2000/XP
- drag-and-drop ruleset editor
- updates directly from bleedingsnort.org