SNORT
Snort is an open-source intrusion detection/prevention system. Essential for network security monitoring and threat detection.
INSTALLATION#
# Ubuntu/Debian apt install snort # From source # https://www.snort.org/downloads
MODES#
SNIFFER MODE#
snort -v # Packet headers snort -vd # Packet data snort -vde # Link layer headers
PACKET LOGGER#
snort -l /var/log/snort # Log packets snort -l /var/log/snort -b # Binary format (pcap)
IDS MODE#
snort -A alert -c /etc/snort/snort.conf -i eth0
IPS MODE#
snort -Q --daq afpacket -c /etc/snort/snort.conf -i eth0:eth1
BASIC USAGE#
START SNORT#
snort -c /etc/snort/snort.conf -i eth0 snort -c /etc/snort/snort.conf -i eth0 -D # Daemon
READ PCAP#
snort -c /etc/snort/snort.conf -r capture.pcap
TEST CONFIG#
snort -c /etc/snort/snort.conf -T
OPTIONS#
-c FILE Configuration file -i INTERFACE Network interface -l DIR Log directory -A MODE Alert mode (fast, full, console, none) -D Daemon mode -q Quiet mode -r FILE Read pcap file -T Test configuration -v Verbose -K Logging mode (pcap, ascii, none)
ALERT MODES#
fast Quick one-line alerts full Full alert format console Print to console cmg Custom format unsock Unix socket none No alerts
RULE STRUCTURE#
BASIC FORMAT#
action protocol src_ip src_port -> dst_ip dst_port (options)
ACTIONS#
alert Generate alert log Log packet pass Ignore packet drop Drop packet (IPS) reject Drop and send RST/ICMP sdrop Silent drop
PROTOCOLS#
tcp TCP protocol udp UDP protocol icmp ICMP protocol ip Any IP protocol
VARIABLES#
$HOME_NET Internal network $EXTERNAL_NET External network $HTTP_SERVERS Web servers $DNS_SERVERS DNS servers any Any address ! Negation
PORTS#
any Any port 80 Single port 1:1024 Port range !80 Not port 80 [80,443,8080] Port list
DIRECTION#
-> Source to destination <> Bidirectional
RULE EXAMPLES#
BASIC ALERT#
alert tcp any any -> any 80 (msg:"HTTP Traffic"; sid:1000001; rev:1;)
CONTENT MATCH#
alert tcp any any -> any 80 (msg:"SQL Injection"; content:"union"; nocase; content:"select"; nocase; sid:1000002;)
HEX CONTENT#
alert tcp any any -> any any (msg:"MZ Header"; content:"|4D 5A|"; depth:2; sid:1000003;)
PCRE MATCH#
alert tcp any any -> any any (msg:"Base64 Data"; pcre:"/[A-Za-z0-9+\/]{50,}={0,2}/"; sid:1000004;)
FLOW CONTROL#
alert tcp any any -> any 80 (msg:"HTTP Request"; flow:established,to_server; content:"GET"; http_method; sid:1000005;)
RULE OPTIONS#
GENERAL#
msg:"message" Alert message sid:1000001 Signature ID rev:1 Revision classtype:type Classification priority:1 Priority level gid:1 Generator ID reference:url,link Reference URL
CONTENT#
content:"string" Match string content:"|4D 5A|" Hex match nocase Case insensitive depth:N Search first N bytes offset:N Start at byte N distance:N N bytes after prev match within:N Within N bytes rawbytes Match raw bytes fast_pattern Set for fast matching
HTTP#
http_method HTTP method http_uri Request URI http_header HTTP headers http_client_body POST body http_cookie Cookies http_stat_code Status code http_content_type Content-Type
FLOW#
flow:established Established connection flow:to_server To server flow:to_client To client flow:stateless Stateless matching flowbits:set,name Set flowbit flowbits:isset,name Check flowbit
DETECTION#
pcre:"/regex/" Perl regex byte_test Test byte value byte_jump Jump bytes isdataat:N Data at offset dsize:N Payload size flags:SF TCP flags threshold Rate limiting detection_filter Detection threshold
THRESHOLD#
threshold:type limit, track by_src, count 10, seconds 60 threshold:type threshold, track by_dst, count 100, seconds 60 threshold:type both, track by_src, count 5, seconds 60
CONFIGURATION#
SNORT.CONF SECTIONS#
# Network variables var HOME_NET 192.168.1.0/24 var EXTERNAL_NET !$HOME_NET var HTTP_SERVERS $HOME_NET var DNS_SERVERS $HOME_NET # Paths var RULE_PATH /etc/snort/rules var LOG_DIR /var/log/snort # Output output alert_fast: alert.log output log_tcpdump: snort.log # Rules include $RULE_PATH/local.rules include $RULE_PATH/community.rules
PREPROCESSORS#
# HTTP inspection preprocessor http_inspect: global iis_unicode_map unicode.map 1252 # Stream reassembly preprocessor stream5_global: track_tcp yes, track_udp yes preprocessor stream5_tcp: policy first
OUTPUT PLUGINS#
output alert_fast: alert.log output alert_full: alert.full output alert_syslog: LOG_AUTH LOG_ALERT output log_tcpdump: snort.log output unified2: filename snort.u2, limit 128
RULE MANAGEMENT#
LOCAL RULES#
# /etc/snort/rules/local.rules alert tcp any any -> any 4444 (msg:"Meterpreter"; sid:9000001;)
ENABLE/DISABLE#
# In snort.conf include $RULE_PATH/emerging-malware.rules # include $RULE_PATH/disabled.rules
PULLEDPORK#
# Rule update tool pulledpork.pl -c /etc/snort/pulledpork.conf pulledpork.pl -c /etc/snort/pulledpork.conf -P
RULE CATEGORIES#
community.rules Community rules emerging-*.rules Emerging Threats registered.rules Snort registered custom.rules Custom rules
LOGGING#
LOG LOCATIONS#
/var/log/snort/alert /var/log/snort/snort.log.*
VIEW ALERTS#
tail -f /var/log/snort/alert cat /var/log/snort/alert | grep "ATTACK"
READ UNIFIED2#
u2spewfoo /var/log/snort/snort.u2.*
BARNYARD2#
barnyard2 -c /etc/snort/barnyard2.conf -d /var/log/snort -f snort.u2
COMMON RULES#
MALWARE C2#
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"Potential C2"; flow:established; content:"POST"; http_method; pcre:"/[A-Za-z0-9+\/]{100,}/P"; sid:9000010;)
SQL INJECTION#
alert tcp any any -> $HTTP_SERVERS $HTTP_PORTS (msg:"SQL Injection"; flow:to_server; content:"union"; nocase; content:"select"; nocase; sid:9000020;)
XSS#
alert tcp any any -> $HTTP_SERVERS $HTTP_PORTS (msg:"XSS Attempt"; flow:to_server; content:"<script"; nocase; sid:9000030;)
SHELLCODE#
alert ip any any -> $HOME_NET any (msg:"Shellcode NOP"; content:"|90 90 90 90 90|"; sid:9000040;)
PERFORMANCE#
# Test performance snort -c snort.conf -r large.pcap --pcap-show # Profile rules snort -c snort.conf --enable-profiling-rules
QUICK REFERENCE#
snort -c snort.conf -i eth0 # IDS mode snort -c snort.conf -r file.pcap # Read pcap snort -c snort.conf -T # Test config snort -v -i eth0 # Sniffer mode snort -l /var/log/snort -i eth0 # Packet logger # Rule format alert proto src port -> dst port (options) content:"string"; nocase; pcre:"/regex/"; flow:established,to_server;
SNORT CHEATSHEET
================
Source: https://cheatsheet.johlem.net
Snort is an open-source intrusion detection/prevention system.
Essential for network security monitoring and threat detection.
INSTALLATION
------------
# Ubuntu/Debian
apt install snort
# From source
# https://www.snort.org/downloads
MODES
=====
SNIFFER MODE
------------
snort -v # Packet headers
snort -vd # Packet data
snort -vde # Link layer headers
PACKET LOGGER
-------------
snort -l /var/log/snort # Log packets
snort -l /var/log/snort -b # Binary format (pcap)
IDS MODE
--------
snort -A alert -c /etc/snort/snort.conf -i eth0
IPS MODE
--------
snort -Q --daq afpacket -c /etc/snort/snort.conf -i eth0:eth1
BASIC USAGE
===========
START SNORT
-----------
snort -c /etc/snort/snort.conf -i eth0
snort -c /etc/snort/snort.conf -i eth0 -D # Daemon
READ PCAP
---------
snort -c /etc/snort/snort.conf -r capture.pcap
TEST CONFIG
-----------
snort -c /etc/snort/snort.conf -T
OPTIONS
-------
-c FILE Configuration file
-i INTERFACE Network interface
-l DIR Log directory
-A MODE Alert mode (fast, full, console, none)
-D Daemon mode
-q Quiet mode
-r FILE Read pcap file
-T Test configuration
-v Verbose
-K Logging mode (pcap, ascii, none)
ALERT MODES
-----------
fast Quick one-line alerts
full Full alert format
console Print to console
cmg Custom format
unsock Unix socket
none No alerts
RULE STRUCTURE
==============
BASIC FORMAT
------------
action protocol src_ip src_port -> dst_ip dst_port (options)
ACTIONS
-------
alert Generate alert
log Log packet
pass Ignore packet
drop Drop packet (IPS)
reject Drop and send RST/ICMP
sdrop Silent drop
PROTOCOLS
---------
tcp TCP protocol
udp UDP protocol
icmp ICMP protocol
ip Any IP protocol
VARIABLES
---------
$HOME_NET Internal network
$EXTERNAL_NET External network
$HTTP_SERVERS Web servers
$DNS_SERVERS DNS servers
any Any address
! Negation
PORTS
-----
any Any port
80 Single port
1:1024 Port range
!80 Not port 80
[80,443,8080] Port list
DIRECTION
---------
-> Source to destination
<> Bidirectional
RULE EXAMPLES
=============
BASIC ALERT
-----------
alert tcp any any -> any 80 (msg:"HTTP Traffic"; sid:1000001; rev:1;)
CONTENT MATCH
-------------
alert tcp any any -> any 80 (msg:"SQL Injection"; content:"union"; nocase; content:"select"; nocase; sid:1000002;)
HEX CONTENT
-----------
alert tcp any any -> any any (msg:"MZ Header"; content:"|4D 5A|"; depth:2; sid:1000003;)
PCRE MATCH
----------
alert tcp any any -> any any (msg:"Base64 Data"; pcre:"/[A-Za-z0-9+\/]{50,}={0,2}/"; sid:1000004;)
FLOW CONTROL
------------
alert tcp any any -> any 80 (msg:"HTTP Request"; flow:established,to_server; content:"GET"; http_method; sid:1000005;)
RULE OPTIONS
============
GENERAL
-------
msg:"message" Alert message
sid:1000001 Signature ID
rev:1 Revision
classtype:type Classification
priority:1 Priority level
gid:1 Generator ID
reference:url,link Reference URL
CONTENT
-------
content:"string" Match string
content:"|4D 5A|" Hex match
nocase Case insensitive
depth:N Search first N bytes
offset:N Start at byte N
distance:N N bytes after prev match
within:N Within N bytes
rawbytes Match raw bytes
fast_pattern Set for fast matching
HTTP
----
http_method HTTP method
http_uri Request URI
http_header HTTP headers
http_client_body POST body
http_cookie Cookies
http_stat_code Status code
http_content_type Content-Type
FLOW
----
flow:established Established connection
flow:to_server To server
flow:to_client To client
flow:stateless Stateless matching
flowbits:set,name Set flowbit
flowbits:isset,name Check flowbit
DETECTION
---------
pcre:"/regex/" Perl regex
byte_test Test byte value
byte_jump Jump bytes
isdataat:N Data at offset
dsize:N Payload size
flags:SF TCP flags
threshold Rate limiting
detection_filter Detection threshold
THRESHOLD
---------
threshold:type limit, track by_src, count 10, seconds 60
threshold:type threshold, track by_dst, count 100, seconds 60
threshold:type both, track by_src, count 5, seconds 60
CONFIGURATION
=============
SNORT.CONF SECTIONS
-------------------
# Network variables
var HOME_NET 192.168.1.0/24
var EXTERNAL_NET !$HOME_NET
var HTTP_SERVERS $HOME_NET
var DNS_SERVERS $HOME_NET
# Paths
var RULE_PATH /etc/snort/rules
var LOG_DIR /var/log/snort
# Output
output alert_fast: alert.log
output log_tcpdump: snort.log
# Rules
include $RULE_PATH/local.rules
include $RULE_PATH/community.rules
PREPROCESSORS
-------------
# HTTP inspection
preprocessor http_inspect: global iis_unicode_map unicode.map 1252
# Stream reassembly
preprocessor stream5_global: track_tcp yes, track_udp yes
preprocessor stream5_tcp: policy first
OUTPUT PLUGINS
--------------
output alert_fast: alert.log
output alert_full: alert.full
output alert_syslog: LOG_AUTH LOG_ALERT
output log_tcpdump: snort.log
output unified2: filename snort.u2, limit 128
RULE MANAGEMENT
===============
LOCAL RULES
-----------
# /etc/snort/rules/local.rules
alert tcp any any -> any 4444 (msg:"Meterpreter"; sid:9000001;)
ENABLE/DISABLE
--------------
# In snort.conf
include $RULE_PATH/emerging-malware.rules
# include $RULE_PATH/disabled.rules
PULLEDPORK
----------
# Rule update tool
pulledpork.pl -c /etc/snort/pulledpork.conf
pulledpork.pl -c /etc/snort/pulledpork.conf -P
RULE CATEGORIES
---------------
community.rules Community rules
emerging-*.rules Emerging Threats
registered.rules Snort registered
custom.rules Custom rules
LOGGING
=======
LOG LOCATIONS
-------------
/var/log/snort/alert
/var/log/snort/snort.log.*
VIEW ALERTS
-----------
tail -f /var/log/snort/alert
cat /var/log/snort/alert | grep "ATTACK"
READ UNIFIED2
-------------
u2spewfoo /var/log/snort/snort.u2.*
BARNYARD2
---------
barnyard2 -c /etc/snort/barnyard2.conf -d /var/log/snort -f snort.u2
COMMON RULES
============
MALWARE C2
----------
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"Potential C2"; flow:established; content:"POST"; http_method; pcre:"/[A-Za-z0-9+\/]{100,}/P"; sid:9000010;)
SQL INJECTION
-------------
alert tcp any any -> $HTTP_SERVERS $HTTP_PORTS (msg:"SQL Injection"; flow:to_server; content:"union"; nocase; content:"select"; nocase; sid:9000020;)
XSS
---
alert tcp any any -> $HTTP_SERVERS $HTTP_PORTS (msg:"XSS Attempt"; flow:to_server; content:"<script"; nocase; sid:9000030;)
SHELLCODE
---------
alert ip any any -> $HOME_NET any (msg:"Shellcode NOP"; content:"|90 90 90 90 90|"; sid:9000040;)
PERFORMANCE
===========
# Test performance
snort -c snort.conf -r large.pcap --pcap-show
# Profile rules
snort -c snort.conf --enable-profiling-rules
QUICK REFERENCE
---------------
snort -c snort.conf -i eth0 # IDS mode
snort -c snort.conf -r file.pcap # Read pcap
snort -c snort.conf -T # Test config
snort -v -i eth0 # Sniffer mode
snort -l /var/log/snort -i eth0 # Packet logger
# Rule format
alert proto src port -> dst port (options)
content:"string"; nocase;
pcre:"/regex/";
flow:established,to_server;
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.