Re: How to support keyword 'pkt_data' in snort rules

"Viktor Chyzhovych -X \(vchyzhov - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]> Mon, 26 Jan 2026 15:13:21 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <LV8PR11MB8769CEA8BABB0E5032432D2CCF93A@LV8PR11MB8769.namprd11.prod.outlook.com>
--===============1597600876669623937==
Content-Language: en-GB
Content-Type: multipart/alternative;
	boundary="_000_LV8PR11MB8769CEA8BABB0E5032432D2CCF93ALV8PR11MB8769namp_"

--_000_LV8PR11MB8769CEA8BABB0E5032432D2CCF93ALV8PR11MB8769namp_
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64

SGVsbG8gV3UsDQoNClRoYW5rIHlvdSBmb3IgcmVhY2hpbmcgb3V0IHRvIHRoZSBTbm9ydC4NCg0K
UmVnYXJkaW5nIHlvdXIgcXVlc3Rpb25zIHdlIHdhbnQgdG8gZXhwbGFpbiBhbmQgZ2l2ZSBzb21l
IHJlY29tbWVuZGF0aW9ucy4NCg0KRm9yIGNvbmZpZ3VyYXRpb24gY2hlY2sgeW91IG5lZWQgdXNl
IHRoZSBuZXh0IG9wdGlvbiAiLS1kdW1wLWNvbmZpZy10ZXh0IGluc3RlYWQgb2YgIi0taGVscC1j
b25maWciIGJlY2F1c2Ugb2Y6DQoNCi0taGVscC1jb25maWcgLSBTaG93cyBhdmFpbGFibGUgY29u
ZmlndXJhdGlvbiBvcHRpb25zIGFuZCB0aGVpciBkZXNjcmlwdGlvbnMgKGhlbHAvZG9jdW1lbnRh
dGlvbikuDQoNCi0tZHVtcC1jb25maWctdGV4dCAtIER1bXBzIHRoZSBhY3R1YWwgbG9hZGVkIGNv
bmZpZ3VyYXRpb24gdmFsdWVzLg0KDQpEb2MgcGFnZTogaHR0cHM6Ly9naXRodWIuY29tL3Nub3J0
My9zbm9ydDMvYmxvYi9tYXN0ZXIvZG9jL3VzZXIvZHVtcF9jb25maWcudHh0DQoNCkFjY29yZGlu
ZyB0byB5b3VyIHRyYWZmaWMsICIvaW5kZXgucGhwIiBpcyBwcmVzZW50IGluIHRoZSBVUkkgKGxp
a2UgR0VUIC9pbmRleC5waHApLCBidXQgeW91ciBydWxlIHdvbid0IGRldGVjdCBpdCB0aGVyZS4g
VGhlICJwa3RfZGF0YSIgb3B0aW9uIHNlYXJjaGVzIGluIHRoZSBtZXNzYWdlIGJvZHksIG5vdCBp
biB0aGUgVVJJIGl0c2VsZi4gVGhpcyBtZWFucyB5b3VyIHJ1bGUgd2lsbCBvbmx5IHRyaWdnZXIg
aWYgIi9pbmRleC5waHAiIGFsc28gYXBwZWFycyBpbiB0aGUgYm9keSBjb250ZW50LCB3aGljaCBp
dCBkb2Vzbid0IGluIHlvdXIgY2FzZS4NClRoaXMgaGFwcGVucyBiZWNhdXNlIGlmIHlvdSB1c2Us
IG1peGluZyAiaHR0cF9oZWFkZXIiIHdpdGggInBrdF9kYXRhIiAod2hpY2ggaW5zcGVjdHMgYm9k
eSBjb250ZW50KSBjcmVhdGVzIGEgY29uZmxpY3QgaW4gaG93IHRoZSBydWxlIHByb2Nlc3NlcyB0
aGUgdHJhZmZpYy4NClRvIHJlc29sdmUgdGhpcywgZWl0aGVyIHVzZSAiaHR0cF91cmkiIGluc3Rl
YWQgb2YgInBrdF9kYXRhIiB0byBpbnNwZWN0IHRoZSBVUkkgb3IgcmVtb3ZlIHRoZSAiaHR0cF9o
ZWFkZXIiIG9wdGlvbiB0byBhdm9pZCBzZWN0aW9uIGNvbmZsaWN0cy4gQWxzbywgeW91IGNhbiBz
cGxpdCBpbnRvIHNlcGFyYXRlIHJ1bGVzIGlmIHlvdSBpbnRlbmQgdG8gaW5zcGVjdCBib3RoIHNl
Y3Rpb25zIGluZGVwZW5kZW50bHkuDQoNCkRvYyBwYWdlOiBodHRwczovL2RvY3Muc25vcnQub3Jn
L3J1bGVzL29wdGlvbnMvcGF5bG9hZC9odHRwL3VyaQ0KDQpSZWNvbW1lbmRlZCBydWxlczoNCg0K
YWxlcnQgaHR0cCBhbnkgYW55IC0+IGFueSAkSFRUUF9QT1JUUyAoIG1zZzoiY2hlY2sgcGt0X2Rh
dGEtMyI7IGh0dHBfaGVhZGVyOyBjb250ZW50OiJBY2NlcHQtRW5jb2Rpbmc6IGd6aXAiOyBodHRw
X3VyaTsgY29udGVudDoiL2luZGV4LnBocCI7IHNpZDoxMDAwMTAwMzsgcmV2OjE7ICkNCg0KQmVz
dCByZWdhcmRzLA0KVmlrdG9yDQoNCg0KDQpHZXQgT3V0bG9vayBmb3IgTWFjIDxodHRwczovL2Fr
YS5tcy9HZXRPdXRsb29rRm9yTWFjPg0KDQpGcm9tOiBTbm9ydC11c2VycyA8c25vcnQtdXNlcnMt
Ym91bmNlc0BsaXN0cy5zbm9ydC5vcmc+IG9uIGJlaGFsZiBvZiDO4rOsIHZpYSBTbm9ydC11c2Vy
cyA8c25vcnQtdXNlcnNAbGlzdHMuc25vcnQub3JnPg0KRGF0ZTogVHVlc2RheSwgMTMgSmFudWFy
eSAyMDI2IGF0IDIwOjI3DQpUbzogc25vcnQtdXNlcnNAbGlzdHMuc25vcnQub3JnIDxzbm9ydC11
c2Vyc0BsaXN0cy5zbm9ydC5vcmc+DQpTdWJqZWN0OiBbU25vcnQtdXNlcnNdIEhvdyB0byBzdXBw
b3J0IGtleXdvcmQgJ3BrdF9kYXRhJyBpbiBzbm9ydCBydWxlcw0KDQpIaSBTbm9ydCBleHBlcnRz
LA0KDQpJIGhhdmUgYSBxdWVzdGlvbiB3aGVuIHVzaW5nICdwa3RfZGF0YScga2V5d29yZCBpbiBz
bm9ydCBydWxlcy4NCkFjY29yZGluZyB0byBodHRwczovL2RvY3Muc25vcnQub3JnL3J1bGVzL29w
dGlvbnMvcGF5bG9hZC9wa3RfZGF0YSwgSSBuZWVkIHRvIHNldCAnc2VhcmNoX2VuZ2luZS5kZXRl
Y3RfcmF3X3RjcCcgdG8gdHJ1ZSB0byBzdXBwb3J0ICdwa3RfZGF0YScgaW4gc29ucnQgcnVsZXMu
DQpCdXQgYWZ0ZXIgSSBhZGRlZCB0aGlzIHNldHRpbmcgdG8gY29uZmlndXJhdGlvbiwgaXQgc2Vl
bXMgbm90IHdvcmtpbmcuDQpQbHMgaGVscCB0byBjaGVjayB3aHkgdGhlIGNvbmZpZ3VyYXRpb24g
bm90IGNoZW5nZWQgaW4gbXkgd29ya2luZyBlbnYsIFRoYW5rcw0KDQpUaGUgc25vcnQgdmVyc2lv
biBpcyB2My43LjQuMC4gSGVyZSBpcyB3aGF0IEkgdHJpZWQ6DQooMSkgYWRkIGNoYW5nZSB0byBz
bm9ydC5sdWEgZmlsZToNCiAgICBhZGQgImluY2x1ZGUoJ21heF9kYXRlY3QubHVhJykiIG9yICJz
ZWFyY2hfZW5naW5lLmRldGVjdF9yYXdfdGNwID0gdHJ1ZSIgb3IgInNlYXJjaF9lbmdpbmUgPSB7
IGRldGVjdF9yYXdfdGNwID0gdHJ1ZSB9Ig0KKDIpIGFkZCBwYXJhbWV0ZXIgaW4gY29tbWFuZA0K
ICAgIGFkZCAiLS1sdWEgJ3NlYXJjaF9lbmdpbmUuZGV0ZWN0X3Jhd190Y3AgPSB0cnVlJyIgb3Ig
Ii0tdHdlYWtzIG1heF9kZXRlY3QiDQpBZnRlciBkb2luZyBhYm92ZSwgSSBjaGVja2VkIGNvbmZp
Z3VyYXRpb24gYnkgdXNpbmcgIi0taGVscC1jb25maWcgc2VhcmNoX2VuZ2luZSB8Z3JlcCB0Y3Ai
LCBhbmQgZ2V0IHRoZSBvdXRwdXQ6DQogICAgYm9vbCBzZWFyY2hfZW5naW5lLmRldGVjdF9yYXdf
dGNwID0gZmFsc2U6IGRldGVjdCBvbiBUQ1AgcGF5bG9hZCBiZWZvcmUgcmVhc3NlbWJseQ0KDQpJ
IGFsc28gY2hlY2tlZCB3aXRoIHNvbWUgc2ltcGxlIHBjYXAgd2l0aCBmb2xsb3dpbmcgc25vcnQg
cnVsZXMsIGFuZCBzZWVtcyBubyBtYXR0ZXIgaG93IHRoZSBjb25maWd1cmF0aW9uIGNoYW5nZWQs
IHRoZSAzcmQgcnVsZSh3aXRoICdwa3RfZGF0YScgaW4gcnVsZSkgbmV2ZXIgbWF0Y2hlZDoNCiAg
ICBhbGVydCB0Y3AgYW55IGFueSAtPiBhbnkgJEhUVFBfUE9SVFMgKCBtc2c6ImNoZWNrIHBrdF9k
YXRhLTEiOyBjb250ZW50OiIvaW5kZXgucGhwIjsgY29udGVudDoiQWNjZXB0LUVuY29kaW5nOiBn
emlwIjsgc2lkOjEwMDAxMDAxOyByZXY6MTsgKQ0KICAgIGFsZXJ0IHRjcCBhbnkgYW55IC0+IGFu
eSAkSFRUUF9QT1JUUyAoIG1zZzoiY2hlY2sgcGt0X2RhdGEtMiI7IGh0dHBfdXJpOyBjb250ZW50
OiIvaW5kZXgucGhwIjsgaHR0cF9oZWFkZXI7IGNvbnRlbnQ6IkFjY2VwdC1FbmNvZGluZzogZ3pp
cCI7IHNpZDoxMDAwMTAwMjsgcmV2OjE7ICkNCiAgICBhbGVydCB0Y3AgYW55IGFueSAtPiBhbnkg
JEhUVFBfUE9SVFMgKCBtc2c6ImNoZWNrIHBrdF9kYXRhLTMiOyBodHRwX2hlYWRlcjsgY29udGVu
dDoiQWNjZXB0LUVuY29kaW5nOiBnemlwIjsgcGt0X2RhdGE7IGNvbnRlbnQ6Ii9pbmRleC5waHAi
OyBzaWQ6MTAwMDEwMDM7IHJldjoxOyApDQpUaGUgcGNhcCBpcyBhdHRhY2hlZCB0byB0aGUgbWFp
bC4NCg0KQmVzdCBSZWdhcmRzLA0KV3UgQ2hhbw0KDQoNCg0K

--_000_LV8PR11MB8769CEA8BABB0E5032432D2CCF93ALV8PR11MB8769namp_
Content-Type: text/html; charset="gb2312"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dgb2312">
</head>
<body>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
Hello Wu,</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
Thank you for reaching out to the Snort.</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
Regarding your questions we want to explain and give some recommendations.<=
/div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
For configuration check you need use the next option &quot;--dump-config-te=
xt instead of &quot;--help-config&quot; because of:</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
--help-config - Shows available configuration options and their description=
s (help/documentation).</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
--dump-config-text - Dumps the actual loaded configuration values.</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
Doc page: <u>https://github.com/snort3/snort3/blob/master/doc/user/dump_con=
fig.txt</u></div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
According to your traffic, &quot;/index.php&quot; is present in the URI (li=
ke GET /index.php), but your rule won't detect it there. The &quot;pkt_data=
&quot; option searches in the message body, not in the URI itself. This mea=
ns your rule will only trigger if &quot;/index.php&quot; also
 appears in the body content, which it doesn't in your case.&nbsp;</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
This happens because if you use, mixing &quot;http_header&quot; with &quot;=
pkt_data&quot; (which inspects body content) creates a conflict in how the =
rule processes the traffic.</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
To resolve this, either use &quot;http_uri&quot; instead of &quot;pkt_data&=
quot; to inspect the URI or remove the &quot;http_header&quot; option to av=
oid section conflicts. Also, you can split into separate rules if you inten=
d to inspect both sections independently.</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
Doc page: <u>https://docs.snort.org/rules/options/payload/http/uri</u></div=
>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
Recommended rules:</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
alert http any any -&gt; any $HTTP_PORTS ( msg:&quot;check pkt_data-3&quot;=
; http_header; content:&quot;Accept-Encoding: gzip&quot;; http_uri; content=
:&quot;/index.php&quot;; sid:10001003; rev:1; )</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
Best regards,</div>
<div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: =
12pt; color: rgb(0, 0, 0);">
Viktor</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id=3D"ms-outlook-mobile-signature">
<p style=3D"direction: ltr; margin: 0in 0in 0.0001pt; font-family: Aptos, s=
ans-serif; font-size: 12pt;">
Get <a href=3D"https://aka.ms/GetOutlookForMac" data-outlook-id=3D"aff7c8ca=
-f9a5-4de4-9e09-1c0cfceb23d2" style=3D"margin-top: 0px; margin-bottom: 0px;=
">
Outlook for Mac </a></p>
</div>
<div id=3D"mail-editor-reference-message-container">
<div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"di=
rection: ltr;">
</div>
<div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"te=
xt-align: left; padding: 3pt 0in 0in; border-width: 1pt medium medium; bord=
er-style: solid none none; border-color: rgb(181, 196, 223) currentcolor cu=
rrentcolor; font-family: Aptos; font-size: 12pt; color: black;">
<b>From: </b>Snort-users &lt;[email protected]&gt; on beh=
alf of =CE=E2=B3=AC via Snort-users &lt;[email protected]&gt;<br>
<b>Date: </b>Tuesday, 13 January 2026 at 20:27<br>
<b>To: </b>[email protected] &lt;[email protected]&gt;<=
br>
<b>Subject: </b>[Snort-users] How to support keyword 'pkt_data' in snort ru=
les<br>
<br>
</div>
<div id=3D"spnEditorContent">
<div style=3D"margin: 0px;">Hi Snort experts,</div>
<div style=3D"direction: ltr; margin: 0px;"><br>
</div>
<div style=3D"margin: 0px;">I have a question when using 'pkt_data' keyword=
 in snort rules.</div>
<div style=3D"margin: 0px;">According to <a href=3D"https://docs.snort.org/=
rules/options/payload/pkt_data" data-outlook-id=3D"31be8314-6898-467b-ab99-=
092c2dc05229">
https://docs.snort.org/rules/options/payload/pkt_data</a>, I need to set 's=
earch_engine.detect_raw_tcp' to true to support 'pkt_data' in sonrt rules.&=
nbsp;</div>
<div style=3D"margin: 0px;">But after I added this setting to configuration=
, it seems not working.&nbsp;</div>
<div style=3D"margin: 0px;">Pls help to check why the configuration not che=
nged in my working env, Thanks</div>
<div style=3D"direction: ltr; margin: 0px;"><br>
</div>
<div style=3D"margin: 0px;">The snort version is v3.7.4.0. Here is what I t=
ried:</div>
<div style=3D"margin: 0px;">(1) add change to snort.lua file:</div>
<div style=3D"margin: 0px;">&nbsp; &nbsp; add &quot;<i>include('max_datect.=
lua')</i>&quot; or &quot;<i>search_engine.detect_raw_tcp =3D true</i>&quot;=
 or &quot;<i>search_engine =3D { detect_raw_tcp =3D true }</i>&quot;</div>
<div style=3D"margin: 0px;">(2) add parameter in command</div>
<div style=3D"margin: 0px;">&nbsp; &nbsp; add &quot;<i>--lua 'search_engine=
.detect_raw_tcp =3D true'</i>&quot; or &quot;<i>--tweaks max_detect</i>&quo=
t;</div>
<div style=3D"margin: 0px;">After doing above, I checked configuration by u=
sing &quot;<i>--help-config search_engine |grep tcp</i>&quot;, and get the =
output:</div>
<div style=3D"margin: 0px;"><span style=3D"background-color: rgb(255, 255, =
255);">&nbsp; &nbsp;
</span><span style=3D"background-color: rgb(255, 245, 102);">bool search_en=
gine.detect_raw_tcp =3D
<b>false</b>: detect on TCP payload before reassembly</span></div>
<div style=3D"direction: ltr; margin: 0px;"><br>
</div>
<div style=3D"margin: 0px;">I also checked with some simple pcap with follo=
wing snort rules, and seems no matter how the configuration changed, the 3r=
d rule(with 'pkt_data' in rule) never matched:</div>
<div style=3D"margin: 0px;">&nbsp; &nbsp; alert tcp any any -&gt; any $HTTP=
_PORTS ( msg:&quot;check pkt_data-1&quot;; content:&quot;/index.php&quot;; =
content:&quot;Accept-Encoding: gzip&quot;; sid:10001001; rev:1; )</div>
<div style=3D"margin: 0px;">&nbsp; &nbsp; alert tcp any any -&gt; any $HTTP=
_PORTS ( msg:&quot;check pkt_data-2&quot;; http_uri; content:&quot;/index.p=
hp&quot;; http_header; content:&quot;Accept-Encoding: gzip&quot;; sid:10001=
002; rev:1; )</div>
<div style=3D"margin: 0px;">&nbsp; &nbsp; alert tcp any any -&gt; any $HTTP=
_PORTS ( msg:&quot;check pkt_data-3&quot;; http_header; content:&quot;Accep=
t-Encoding: gzip&quot;; pkt_data; content:&quot;/index.php&quot;; sid:10001=
003; rev:1; )</div>
<div style=3D"margin: 0px;">The pcap is attached to the mail.</div>
<div style=3D"direction: ltr; margin: 0px;"><br>
</div>
</div>
<div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"li=
ne-height: 1.7; margin: 0px; font-family: Arial; font-size: 14px; color: rg=
b(0, 0, 0);">
Best Regards,</div>
<div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"li=
ne-height: 1.7; margin: 0px; font-family: Arial; font-size: 14px; color: rg=
b(0, 0, 0);">
Wu Chao</div>
<pre><div class=3D"ms-outlook-mobile-reference-message skipProofing" style=
=3D"line-height: 1.7; font-size: 14px; color: rgb(0, 0, 0);"><br>=0A=
</div></pre>
</div>
</body>
</html>

--_000_LV8PR11MB8769CEA8BABB0E5032432D2CCF93ALV8PR11MB8769namp_--

--===============1597600876669623937==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============1597600876669623937==--