This can be very subjective on what really needs to be omitted. I think
going through and removing what you don't need first, is a good first
step. Then start the procedure of really scrutinizing the remainder of
the rules.

If you are not running IIS then dump the IIS.rules. If you're not
running Cold Fusion, then dump those. Do that on your first round. Then
start the tedious task of removing individual rules that you know you
really don't care about, or need.

There are a couple of things you can do to Improve performance too, if
that is a concern.

I have been studying Snort on Windows for a couple of weeks now and have
gotten a pretty good idea of how it works and how to deploy it.

If it ok, I would like to ask a couple of questions to clarify a couple

First, after looking through the rules, I noticed a wide variety of
for a cross section of platforms. I understand that they were written
way on purpose. My question is, is it ok to go through and edit these
to remove all of the *nix related stuff? Our network is composed of 20
nodes. All Windows 2000 with 1 Windows 2000 Server. The server is a DC
not a web/mail, etc. server. So, I was thinking that to improve
and reduce false positives, I could go through and edit the rules
only the Win32 stuff in. Is this a good route to go?

The second question is as follows. Given the pretty basic network setup
described above, can someone give my a good idea of which rules are good
start with (before I get into editing them)? Obviously, some like X11
web-coldfusion would not be necessary. What would be a good starting
Any input here?

Thank you to anyone that is able to help.

Low man on the totem pole

