There's not enough Snort tutorials on YT, thanks for putting this out there. I would love to see a live demo of an attack taking place (real time) and the IDS/IPS vm capturing this as it goes down.
@MyDFIR9 ай бұрын
That is a fantastic idea ❤️
@joshuaspeshock4636 Жыл бұрын
Amazing walkthrough from start to finish. Thank you for providing the documentation my man to follow along and ending the video with ideas to add onto this and expand but asking questions on what content we would like to see and the enthusiasm to create it. Hands down the cybersecurity community is very thankful to have you and as always thank you so much for what you do for the community and looking forward to more technical tool and scenario walkthroughs like these and more to come great work!
@MyDFIR Жыл бұрын
Thanks Joshua! More to come for sure ❤️
@olayinkaojo88287 ай бұрын
Hi MyDFIR. This tutorial is a master class, especially for Snort 3! Simple, straight forward, and strong. Thanks
@MyDFIR7 ай бұрын
Thank you for watching ❤️
@lennartschneider17108 ай бұрын
Thanks to your video I was able to finish my assignment on snort! 😭
@MyDFIR8 ай бұрын
Nice!
@kdyxs22 ай бұрын
Best instruction video on snort3. Thanks!
@MyDFIR2 ай бұрын
Wow, thanks!
@fredokaych8 ай бұрын
This is great. Could you be kind enough to prepare another video on Snort 3 IPS, especially using NFQUEUE?
@TheSilentLearner786 Жыл бұрын
Sir , defenetly we need the splunk tutorial this is so special❤
@MyDFIR Жыл бұрын
👀 thanks for watching!
@gmontenegro9711 Жыл бұрын
Sweet this is great content!
@MyDFIR Жыл бұрын
Glad you enjoy it!
@claudiotonelli77098 ай бұрын
Compliment!!! Very good video!!
@MyDFIR8 ай бұрын
Thank you very much!
@toasanseun4704 ай бұрын
very detailed
@MyDFIR4 ай бұрын
Glad you think so!
@henry-c8o Жыл бұрын
im down for fowarding the logs into splunk / digest it into splunk super cool!
@infosecvolts Жыл бұрын
+1 please make it @MyDFIR
@MyDFIR Жыл бұрын
👀👀 Thanks for watching!!
@zssz-ftc3 күн бұрын
Another great video. Thanks. Snort is a good tool to use. Is it possible to monitor 2 networks with snort at the same time?
@MyDFIR3 күн бұрын
Yup! You'll need another network adapter though and Snort must be accessible to both networks.
@batista98854 Жыл бұрын
Thanks from India.
@MyDFIR Жыл бұрын
Thanks for watching!
@Javaman928 ай бұрын
WOW, you really know your stuff.
@MyDFIR8 ай бұрын
Haha thanks! I know very little still... but I try!
@sertac52625 ай бұрын
Hello, first of all, thank you for the video; it was very helpful for me. I would like to take the output from Snort and save it in JSON format. Could you please guide me on how to do this? Thank you in advance.
@rockycool2225 ай бұрын
Can you please make a video to integrate snort v3 to splunk as well .... thank you
@olayinkaojo88286 ай бұрын
Please can you provide a guide on setting rules to detect and prevent DDoS and Sql injection attacks, and storing the alert in CSV file? Thanks
@rohithroyal8777 Жыл бұрын
Hii MYDFIR I have been working in supporting project nearly 2 years.Now I want to shift my career into cybersecurity. Can you suggest which cybesecurity is best I mean cloud security analyst, or network analyst or Soc analyst.plz suggest me...
@Jon_Lopez_io Жыл бұрын
Can you make a video in installing OpenVas?
@MyDFIR Жыл бұрын
Great suggestion!
@Jon_Lopez_io Жыл бұрын
@@MyDFIRthank you for your knowledge
@oscarmarcos12173 ай бұрын
how can i get back my eneric-receive-offload and large-receive-offload switch on again???
@johnvardy9559 Жыл бұрын
Which one operation system you used on everyday tasks?
@MyDFIR Жыл бұрын
I use windows 10 for everyday tasks as it just works. If i need linux capabilities ill use WSL for it and lab stuff ill use whatever is needed
@AceS_348 ай бұрын
When you mentioned that you are using a ubuntu server, is that also the ubuntu desktop with the graphical design or the server type?
@MyDFIR8 ай бұрын
Server type, you can use the GUI if you are not comfortable with CLI 👍 That is what I did in the beginning until I quickly realized in the real world, everyone is using CLI which is mainly the reason why I do it this way in my videos.
@AceS_348 ай бұрын
@@MyDFIR Ah thank you, that explains it.
@princeVEGE6 ай бұрын
Do you have use ubuntu distribution or can I use another like kali linux?
@MyDFIR6 ай бұрын
The list of compatible flavors are on their site, I would suggest looking into that to make sure
@guerospinoza-qn1rt Жыл бұрын
Hi yeaterday snort worked well ,today i got Analyzer: Failed to start DAQ instance
@MyDFIR Жыл бұрын
Services are running? Have you tried restarting? Try to view the logs and see if it tells you why DAQ stopped.
@guerospinoza-qn1rt Жыл бұрын
Thank you i will @@MyDFIR
@travislodes5378 Жыл бұрын
Any chance you could update this with an install for kali
@freaksnz1 Жыл бұрын
It will be the same as Ubuntu server uses Debian base os and so does kali
@olayinkaojo88287 ай бұрын
Please can you help me with installing Snort 3 on Ubuntu 24.04. I am currently in the Thesis phase of my study and need Snort. The error am receiving is at the installation of the prerequisite phase. "E: unable to locate package zlib1g-dev" and also libtool and libmnl-dev. Thanks
@MyDFIR7 ай бұрын
Do double check your spelling for those packages
@guerospinoza-qn1rt Жыл бұрын
Hi , i am a 63 years old and trying to learn a little bit about cyber , so i'm a newbie in this field, what i'm trying to understand about a snot how is it running ? Why i can't enable it with systemctl systemctl enable snort.service Failed to enable unit: Unit file snort.service does not exist? And how to monitor it , or i have to look everytime in snort log , how do i get an alert if something wrong ? Thank you very much.
@MyDFIR Жыл бұрын
Welcome! Snort must be installed first before you can enable its service. To monitor the alerts coming in real time, you will need to use another tool such as Splunk to alert you or sguil - hope that helps!
@guerospinoza-qn1rt Жыл бұрын
Thank you very much!@@MyDFIR
@lifesbeautifulisntit2 ай бұрын
i am having issues with the unzip pcap password, i typed infected but its not working
@lifesbeautifulisntit2 ай бұрын
it worked, they changed the password "infected _followed by the date"
@AniketSonwane-h7xКүн бұрын
mydfir i am guy who use vmware for anything i wanted a simple project in kali linux please give me some guidance over it
@MyDFIRКүн бұрын
Can check out the home lab i have on my channel for some inspiration
@vinnys83287 ай бұрын
I cant get snort to create any pcap files any help?
@MyDFIR7 ай бұрын
Are you listening on the correct interface?
@vinnys83287 ай бұрын
@@MyDFIR I have the -i set to my interface so im not sure whats going on