Re: [SUSPECTED SPAM] [Snort-users] Snort HTTPS

"Joel Esler \(jesler\) via Snort-devel" <[email protected]> Tue, 12 Mar 2019 20:34:06 +0000
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <FD029977-E8A1-4A2F-861F-64F8084E0927__6220.82491624809$1552423098$gmane$org@cisco.com>

> On Mar 12, 2019, at 4:17 PM, Kai Chan via Snort-users <[email protected]> wrote:
> 
> Can Snort monitor HTTPS sessions, not just the handshake?

It can monitor the handshake, however, not much is useful after that, as it would be encrypted.


> Do you have to pay for rule subscriptions to get this?


No, you'd have to have something decrypting the traffic before it reaches Snort.

--
Joel Esler
Manager, Communities Division
Cisco Talos Intelligence Group
http://www.talosintelligence.com

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!
smime.p7s (application/pkcs7-signature, 2.9 KB) - not displayed