Re: [SUSPECTED SPAM] [Snort-users] Snort HTTPS
"Joel Esler \(jesler\) via Snort-devel" <[email protected]> Tue, 12 Mar 2019 20:34:06 +0000
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <FD029977-E8A1-4A2F-861F-64F8084E0927__6220.82491624809$1552423098$gmane$org@cisco.com> |
> On Mar 12, 2019, at 4:17 PM, Kai Chan via Snort-users <[email protected]> wrote: > > Can Snort monitor HTTPS sessions, not just the handshake? It can monitor the handshake, however, not much is useful after that, as it would be encrypted. > Do you have to pay for rule subscriptions to get this? No, you'd have to have something decrypting the traffic before it reaches Snort. -- Joel Esler Manager, Communities Division Cisco Talos Intelligence Group http://www.talosintelligence.com _______________________________________________ Snort-devel mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-devel Please visit http://blog.snort.org for the latest news about Snort!
smime.p7s
(application/pkcs7-signature, 2.9 KB) - not displayed