← All cheat sheets

SNORT

Plain-text reference · 8 KB. Read it, search it (Ctrl-F) or print it.

Snort is an open-source intrusion detection/prevention system.
Essential for network security monitoring and threat detection.

INSTALLATION#

# Ubuntu/Debian
apt install snort

# From source
# https://www.snort.org/downloads

MODES#


            

SNIFFER MODE#

snort -v                              # Packet headers
snort -vd                             # Packet data
snort -vde                            # Link layer headers

PACKET LOGGER#

snort -l /var/log/snort               # Log packets
snort -l /var/log/snort -b            # Binary format (pcap)

IDS MODE#

snort -A alert -c /etc/snort/snort.conf -i eth0

IPS MODE#

snort -Q --daq afpacket -c /etc/snort/snort.conf -i eth0:eth1

BASIC USAGE#


            

START SNORT#

snort -c /etc/snort/snort.conf -i eth0
snort -c /etc/snort/snort.conf -i eth0 -D        # Daemon

READ PCAP#

snort -c /etc/snort/snort.conf -r capture.pcap

TEST CONFIG#

snort -c /etc/snort/snort.conf -T

OPTIONS#

-c FILE         Configuration file
-i INTERFACE    Network interface
-l DIR          Log directory
-A MODE         Alert mode (fast, full, console, none)
-D              Daemon mode
-q              Quiet mode
-r FILE         Read pcap file
-T              Test configuration
-v              Verbose
-K              Logging mode (pcap, ascii, none)

ALERT MODES#

fast            Quick one-line alerts
full            Full alert format
console         Print to console
cmg             Custom format
unsock          Unix socket
none            No alerts

RULE STRUCTURE#


            

BASIC FORMAT#

action protocol src_ip src_port -> dst_ip dst_port (options)

ACTIONS#

alert           Generate alert
log             Log packet
pass            Ignore packet
drop            Drop packet (IPS)
reject          Drop and send RST/ICMP
sdrop           Silent drop

PROTOCOLS#

tcp             TCP protocol
udp             UDP protocol
icmp            ICMP protocol
ip              Any IP protocol

VARIABLES#

$HOME_NET       Internal network
$EXTERNAL_NET   External network
$HTTP_SERVERS   Web servers
$DNS_SERVERS    DNS servers
any             Any address
!               Negation

PORTS#

any             Any port
80              Single port
1:1024          Port range
!80             Not port 80
[80,443,8080]   Port list

DIRECTION#

->              Source to destination
<>              Bidirectional

RULE EXAMPLES#


            

BASIC ALERT#

alert tcp any any -> any 80 (msg:"HTTP Traffic"; sid:1000001; rev:1;)

CONTENT MATCH#

alert tcp any any -> any 80 (msg:"SQL Injection"; content:"union"; nocase; content:"select"; nocase; sid:1000002;)

HEX CONTENT#

alert tcp any any -> any any (msg:"MZ Header"; content:"|4D 5A|"; depth:2; sid:1000003;)

PCRE MATCH#

alert tcp any any -> any any (msg:"Base64 Data"; pcre:"/[A-Za-z0-9+\/]{50,}={0,2}/"; sid:1000004;)

FLOW CONTROL#

alert tcp any any -> any 80 (msg:"HTTP Request"; flow:established,to_server; content:"GET"; http_method; sid:1000005;)

RULE OPTIONS#


            

GENERAL#

msg:"message"           Alert message
sid:1000001            Signature ID
rev:1                   Revision
classtype:type          Classification
priority:1              Priority level
gid:1                   Generator ID
reference:url,link      Reference URL

CONTENT#

content:"string"        Match string
content:"|4D 5A|"       Hex match
nocase                  Case insensitive
depth:N                 Search first N bytes
offset:N                Start at byte N
distance:N              N bytes after prev match
within:N                Within N bytes
rawbytes                Match raw bytes
fast_pattern            Set for fast matching

HTTP#

http_method             HTTP method
http_uri                Request URI
http_header             HTTP headers
http_client_body        POST body
http_cookie             Cookies
http_stat_code          Status code
http_content_type       Content-Type

FLOW#

flow:established        Established connection
flow:to_server          To server
flow:to_client          To client
flow:stateless          Stateless matching
flowbits:set,name       Set flowbit
flowbits:isset,name     Check flowbit

DETECTION#

pcre:"/regex/"          Perl regex
byte_test               Test byte value
byte_jump               Jump bytes
isdataat:N              Data at offset
dsize:N                 Payload size
flags:SF                TCP flags
threshold               Rate limiting
detection_filter        Detection threshold

THRESHOLD#

threshold:type limit, track by_src, count 10, seconds 60
threshold:type threshold, track by_dst, count 100, seconds 60
threshold:type both, track by_src, count 5, seconds 60

CONFIGURATION#


            

SNORT.CONF SECTIONS#

# Network variables
var HOME_NET 192.168.1.0/24
var EXTERNAL_NET !$HOME_NET
var HTTP_SERVERS $HOME_NET
var DNS_SERVERS $HOME_NET

# Paths
var RULE_PATH /etc/snort/rules
var LOG_DIR /var/log/snort

# Output
output alert_fast: alert.log
output log_tcpdump: snort.log

# Rules
include $RULE_PATH/local.rules
include $RULE_PATH/community.rules

PREPROCESSORS#

# HTTP inspection
preprocessor http_inspect: global iis_unicode_map unicode.map 1252

# Stream reassembly
preprocessor stream5_global: track_tcp yes, track_udp yes
preprocessor stream5_tcp: policy first

OUTPUT PLUGINS#

output alert_fast: alert.log
output alert_full: alert.full
output alert_syslog: LOG_AUTH LOG_ALERT
output log_tcpdump: snort.log
output unified2: filename snort.u2, limit 128

RULE MANAGEMENT#


            

LOCAL RULES#

# /etc/snort/rules/local.rules
alert tcp any any -> any 4444 (msg:"Meterpreter"; sid:9000001;)

ENABLE/DISABLE#

# In snort.conf
include $RULE_PATH/emerging-malware.rules
# include $RULE_PATH/disabled.rules

PULLEDPORK#

# Rule update tool
pulledpork.pl -c /etc/snort/pulledpork.conf
pulledpork.pl -c /etc/snort/pulledpork.conf -P

RULE CATEGORIES#

community.rules         Community rules
emerging-*.rules        Emerging Threats
registered.rules        Snort registered
custom.rules            Custom rules

LOGGING#


            

LOG LOCATIONS#

/var/log/snort/alert
/var/log/snort/snort.log.*

VIEW ALERTS#

tail -f /var/log/snort/alert
cat /var/log/snort/alert | grep "ATTACK"

READ UNIFIED2#

u2spewfoo /var/log/snort/snort.u2.*

BARNYARD2#

barnyard2 -c /etc/snort/barnyard2.conf -d /var/log/snort -f snort.u2

COMMON RULES#


            

MALWARE C2#

alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"Potential C2"; flow:established; content:"POST"; http_method; pcre:"/[A-Za-z0-9+\/]{100,}/P"; sid:9000010;)

SQL INJECTION#

alert tcp any any -> $HTTP_SERVERS $HTTP_PORTS (msg:"SQL Injection"; flow:to_server; content:"union"; nocase; content:"select"; nocase; sid:9000020;)

XSS#

alert tcp any any -> $HTTP_SERVERS $HTTP_PORTS (msg:"XSS Attempt"; flow:to_server; content:"<script"; nocase; sid:9000030;)

SHELLCODE#

alert ip any any -> $HOME_NET any (msg:"Shellcode NOP"; content:"|90 90 90 90 90|"; sid:9000040;)

PERFORMANCE#

# Test performance
snort -c snort.conf -r large.pcap --pcap-show

# Profile rules
snort -c snort.conf --enable-profiling-rules

QUICK REFERENCE#

snort -c snort.conf -i eth0           # IDS mode
snort -c snort.conf -r file.pcap      # Read pcap
snort -c snort.conf -T                # Test config
snort -v -i eth0                      # Sniffer mode
snort -l /var/log/snort -i eth0       # Packet logger

# Rule format
alert proto src port -> dst port (options)
content:"string"; nocase;
pcre:"/regex/";
flow:established,to_server;

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.