Skip to content

Entry

Snort

Appears in 9 awesome lists

Snort is a free and open source network intrusion prevention system (NIPS) and network intrusion detection system (NIDS)created by Martin Roesch in 1998. Snort is now developed by Sourcefire, of which Roesch is the founder and CTO. In 2009, Snort entered InfoWorld's Open Source Hall of Fame as one…

Open snort.org

Found in these lists

Awesome Cybersecurity Blue Team

Section: Network Security Monitoring (NSM) · Widely-deployed, Free Software IPS capable of real-time packet analysis, traffic logging, and custom rule-based triggers.

StaleScore 53

Awesome Cybersecurity Blue Team - CN

Section: 网络安全监控(NSM) · 广泛部署的免费IPS软件,能够进行实时数据包分析,流量记录和基于规则的自定义触发器

StaleScore 47

Awesome Home Networking

Section: IPS/IDS

SlowScore 55

Awesome OSINT

Section: ↑ Privacy and Encryption Tools

FreshScore 89

Awesome Pcaptools

Section: Traffic Analysis/Inspection · Snort is an open source network intrusion prevention and detection system (IDS/IPS) developed by Sourcefire, now owned by Cisco. Combining the benefits of signature, protocol and anomaly- based inspection, Snort is the most widely deployed IDS/IPS technology worldwide. With millions of downloads…

SlowScore 60

Awesome Security

Section: IDS / IPS / Host IDS / Host IPS · Snort is a free and open source network intrusion prevention system (NIPS) and network intrusion detection system (NIDS)created by Martin Roesch in 1998. Snort is now developed by Sourcefire, of which Roesch is the founder and CTO. In 2009, Snort entered InfoWorld's Open Source Hall of Fame as one…

SlowScore 70

Awesome Threat Detection and Hunting

Section: Network Monitoring · (github) - A network intrusion detection tool

SlowScore 61

Awesome Privacy

Section: Linux Defenses · Open source intrusion prevention system capable of real-time traffic analysis and packet logging.

FreshScore 91

Table of Contents

Section: Security · Snort is a free and open source network intrusion prevention system (NIPS) and network intrusion detection system (NIDS) created by Martin Roesch in 1998.

SlowScore 61

Wireshark

Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Wireshark is very similar to tcpdump, but has a graphical front-end, plus some integrated sorting and filtering options.

In 20 listsDetails

Zeek

(formerly Bro) is an open source software platform that provides compact, high-fidelity transaction logs, file content, and fully customized output to analysts, from the smallest home office to the largest, fastest research and commercial networks. From the FAQ: "Zeek provides a comprehensive…

In 6 listsDetails

Maltrail

A malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails and featuring an reporting and analysis interface.

In 5 listsDetails

Stenographer

Packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. It stores as much history as it possible, managing disk usage, and deleting when disk limits are hit. It's ideal for capturing the traffic just before and during…

In 5 listsDetails

Tsunami

A general purpose network security scanner with an extensible plugin system for detecting high severity RCE-like vulnerabilities with high confidence. Custom detectors for finding vulnerabilities (e.g. open APIs) can be added.

In 3 lists

Arkime

Augments your current security infrastructure to store and index network traffic in standard PCAP format, providing fast, indexed access.

In 4 lists

VAST

Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.

In 4 lists

Suricata

Suricata is a free and open source, mature, fast and robust network threat detection engine. The Suricata engine is capable of real time intrusion detection (IDS), inline intrusion prevention (IPS), network security monitoring (NSM) and offline pcap processing.

In 5 lists