Eye House - Snort IDS Rule Writing Lab

Week 7 - Incident Response Capstone Back to Week 7

Mission Objectives

Snort Console
Traffic Generator
==========================================
SNORT IDS RULE WRITING WORKSTATION
==========================================
Version: 2.9.18
Rule Path: /etc/snort/rules/local.rules
PCAP Library: Available
System Ready. Type 'help' for available commands.
analyst@snort:~$
==========================================
TRAFFIC GENERATOR CONSOLE
==========================================
Available PCAPs:
- capture.pcap (mixed traffic)
- icmp_test.pcap (ICMP packets)
- ssh_brute.pcap (SSH brute force)
- sql_injection.pcap (SQL injection attempts)
System Ready. Use 'replay [filename]' to generate traffic.
analyst@traffic:~$

LAB COMPLETE!

You have mastered Snort IDS rule writing.

+25 XP