Re: [Snort-sigs] [Snort-users] Snort HTTPS

পথিক via Snort-devel <[email protected]> Thu, 14 Mar 2019 17:00:08 +0600
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <CAA+QOitxjR4=uEhbkmvfyupqoAo62cWQLo+dVz+YxXRgvLpimg@mail.gmail.com>
HIDS can do before encryption and after decryptio.

Motashim Al Razi.

On Wed, 13 Mar 2019, 8:19 pm Kai Chan via Snort-sigs, <
[email protected]> wrote:

> Thanks for clarifying.
>
> Thanks,
> Kai
>
>
> On Tue, Mar 12, 2019, 4:34 PM Joel Esler (jesler) <[email protected]>
> wrote:
>
>>
>>
>> > On Mar 12, 2019, at 4:17 PM, Kai Chan via Snort-users <
>> [email protected]> wrote:
>> >
>> > Can Snort monitor HTTPS sessions, not just the handshake?
>>
>> It can monitor the handshake, however, not much is useful after that, as
>> it would be encrypted.
>>
>>
>> > Do you have to pay for rule subscriptions to get this?
>>
>>
>> No, you'd have to have something decrypting the traffic before it reaches
>> Snort.
>>
>> --
>> Joel Esler
>> Manager, Communities Division
>> Cisco Talos Intelligence Group
>> http://www.talosintelligence.com
>
> _______________________________________________
> Snort-sigs mailing list
> [email protected]
> https://lists.snort.org/mailman/listinfo/snort-sigs
>
> Please visit http://blog.snort.org for the latest news about Snort!
>
> Please follow these rules:
> https://snort.org/faq/what-is-the-mailing-list-etiquette
>
> Visit the Snort.org to subscribe to the official Snort ruleset, make sure
> to stay up to date to catch the most <a href="
> https://snort.org/downloads/#rule-downloads">emerging threats</a>!
>

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!