SNORT rules Advanced Parser for pulledpork

Lone Hacker in Wharehouse by Brian Klug
Lone Hacker in Wharehouse by Brian Klug

Security Onion is an Ubuntu based distribution created to handle a lot of Security task.

One of the security tool installed is SNORT, the best open source Intrusion Detection System (IDS). Security Onion use Pulledpork to get IDS rules and process them.

I wrote a perl script to make advanced modification to the downloaded SNORT rules. This script can handle rule transformation based on regular expression and multiple substitution patterns.

Source code is available on my personal github in snort-rules-customization repository and the package can be downloaded directly from github.

The README file details

Hope someone else find it useful as I did.

Enjoy
@merlos

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.