Since we had some very useful info on how to receive an email from snort logs, let's see the second question: how to dynamically configure a firewall on Windows with the info provided by snort ?

Well, it's possible.

My first thought was to use netsh, the Network Shell native command interface. It's possible, but it is not "user friendly" like iptables or ipchains. Then I found pktfilter.


Full documented, not as powerfull as iptables, but now it's a question of time to configure snort / swatch / pktfilter and finally have it.

It would be nice to hear from you, if anyone will give it a try. I'll keep the list posted.


