Type: Module
Difficulty: Medium
Description:
Snort is the most widely used Open Source Intrusion Detection & Prevention System
and is essential in defining malicious network activity.
This module will cover the need-to-know functionalities of Snort for any security
analyst: Traffic Sniffing, Traffic Logging, Traffic Blocking, PCAP investigation,
and creating IDS/IPS rules. You will learn how to use Snort for different purposes
and create IDS/IPS rules for different threat scenarios. By the End of the module,
you will master your Snort skills and be able to detect anomalies and threats and
stop malicious activities.
Web link: https://tryhackme.com/module/snort