SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsSnort is a lightweight Network Intrusion Detection System, capable of performing realtime traffic analysis and packet logging on IP networks.'1 Snort spies on all of the packets going through a specific network that it is set up to monitor and alerts when it finds specific predefined patterns (defined in the Rules) that could be malicious. Snort works with many different operating systems and platforms. It can be used as a Packet Sniffer Packet Logger or Network Intrusion Detection System. Snort is very a powerful customizable flexible and scalable tool because of its open-sourced nature. Best of all Snort is free. The purpose of this paper is to detail using Snort as a Network Intrusion Detection System. Unfortunately Snort is not just a simple executable file that one could click next all the way through. There are many different applications that need to be installed to make Snort run. This paper is designed with as much detail as possible to help 'newbies' easily install and configure Snort 1.8.6 on Windows 2000/XP. This document is intended for people with little technical experience. They will be able to successfully install Snort with little difficulty and understand the different steps along the way.