Snort Cheat Sheet
Snort Cheat Sheet
alert, log, pass, activate, dynamic, Send SMB alert to PC -M (PC name or IP address)
Actions
drop, reject, sdrop
ASCII log mode -K
Run in Background -D
Snort Rule Example
Listen to a specific network
-i
log tcp !10.1.1.0/24 any -> 10.1.1.100 (msg: "ftp access";) interface