[Snort-users] Portscan traffic don't appear on BASE - snort 2.9.2.2

Joel Esler jesler at ...1935...
Wed Aug 1 08:51:41 EDT 2012


On Jul 31, 2012, at 1:18 AM, "Dang Le Nam" <lenam.cntp at ...11827...> wrote:
> Please give a your rule  to detect “scan port” on snort. Thanks for share

Please take a look at the scan.rules file, it's available in the Snort rules tarball found on the website.

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20120801/a67c1cb6/attachment.html>


More information about the Snort-users mailing list