Re: Ruleset advice for beginners
Michael Steele via Snort-users <[email protected]> Mon, 22 Jun 2026 16:35:30 +0000 (UTC)
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multipart message in MIME format. --===============7118152410918930080== Content-Type: multipart/alternative; boundary="----=_NextPart_000_0008_01DD0243.9D251360" Content-Language: en-us This is a multipart message in MIME format. ------=_NextPart_000_0008_01DD0243.9D251360 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable There is no way to download a pre-packaged, out-of-the-box ruleset = tailored perfectly to a specific environment right from the start. =20 While the Talos Subscriber ruleset gives you rapid, premium threat = updates, even those rules default primarily to alert actions. This is = intentional; if a ruleset dropped traffic by default, it would instantly = break legitimate services on a home network the moment a false positive = triggered. =20 PulledPork is exactly the tool you need to change this behavior, but its = base policies (Connectivity, Balanced, and Security) are only the = starting point. To move from passive alerts to active blocking (drop = actions), you need to configure PulledPork to rewrite the rule states = for you. =20 Building a custom ruleset that matches your specific network profile = will take a little work, but here is the general approach to get you = started: =20 1. Enable Inline Dropping in Snort First, make sure Snort is actually configured to drop traffic. If Snort = isn't running in inline mode (using DAQ modules like afpacket or nfq), = changing the rules to drop won't do anything=E2=80=94it will still only = log an alert. you need to ensure your execution mode supports blocking. =20 2. Leverage PulledPork's Modification Files Instead of editing the massive ruleset manually every day (which gets = overwritten on every update), you use PulledPork=E2=80=99s built-in = state modification files: dropsid.conf, enablesid.conf, and = disablesid.conf. * dropsid.conf: You can add specific Signature IDs (SIDs) or entire rule = categories here. PulledPork will automatically change the action from = alert to drop every time it downloads a new update. * disablesid.conf: Use this to turn off noisy or irrelevant rules (like = specific server vulnerabilities if you aren't running those servers at = home) to reduce overhead and false positives. =20 3. Start Small and Tune Start by using dropsid.conf on highly reliable, high-severity categories = (like known malware command-and-control communication or active = exploits). Watch your logs closely for a week to catch false positives = before expanding your drop list. =20 Tailoring a ruleset is an iterative process, but utilizing PulledPork to = manage the rule modifications is the standard, efficient way to handle = it. =20 WINSNORT.com Management=E2=80=A6 -- ******************** Established ~ 2003 ********************** * FREE Windows Intrusion Detection System (WinIDS) Tutorials * * ~~ FREE Windows Support Forums ~~ * * Visit @ http://winsnort.com * * Snort: Open Source Network IDS - http://snort.org * ************************************************************** =20 Best regards, Michael... =20 From: Snort-users <[email protected]> On Behalf Of = Jonathan Lee via Snort-users Sent: Thursday, June 18, 2026 12:07 PM To: Peter Lyons <[email protected]> Cc: [email protected] Subject: Re: [Snort-users] Ruleset advice for beginners =20 You have to set block on alert and inline mode or legacy mode=20 Sent from my iPhone On Jun 18, 2026, at 08:50, Peter Lyons via Snort-users = <[email protected] <mailto:[email protected]> > = wrote: =EF=BB=BF=20 About a year ago I installed snort3 and pulledpork on ubuntu 24.04 to = provide better protection on my home network. =20 I registered and used the LightSPD_ruleset, rule_mode=3Dsimple, = ips_policy=3Dbalanced =20 Got it all working, and auto updating the LightSPD ruleset everyday. =20 At the start, I was checking the log $ tail -f /var/snort/alert_json.txt = to see if it was working. =20 So I felt very happy and secure. =20 Then the other day I checked the log file a bit more and noticed the log = file only had alert warnings and no rule actions like block or drop etc. =20 So then I checked the LightSPD_ruleset and noticed that by default the = rule actions are all set to alert warnings. =20 Which means I have to monitor the log file and customize the rules = myself. =20 While I=E2=80=99d call myself a linux enthusiast, I don=E2=80=99t have = the expertise to do that. =20 Is there a way to get a rule set suitable for a home network? =20 I=E2=80=99m thinking there might be a community rule set suitable or pay = for a subscribed Talos ruleset. =20 I=E2=80=99m assuming the subscribed ruleset comes with rule actions to = provide protection, and instant threat updates. Are my options correct?=20 =20 Advise please. PS: I am new to this mailing list. Peter Lyons =20 _______________________________________________ Snort-users mailing list [email protected] <mailto:[email protected]>=20 Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] = <mailto:[email protected]>=20 Please visit http://blog.snort.org to stay current on all the latest = Snort news! Please follow these rules: = https://snort.org/faq/what-is-the-mailing-list-etiquette ------=_NextPart_000_0008_01DD0243.9D251360 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" = xmlns:o=3D"urn:schemas-microsoft-com:office:office" = xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" = xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta = http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta = name=3DGenerator content=3D"Microsoft Word 15 (filtered = medium)"><style><!-- /* Font Definitions */ @font-face {font-family:Wingdings; panose-1:5 0 0 0 0 0 0 0 0 0;} @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Aptos;} @font-face {font-family:Tahoma; panose-1:2 11 6 4 3 5 4 4 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; font-size:12.0pt; font-family:"Aptos",sans-serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:#467886; text-decoration:underline;} span.EmailStyle20 {mso-style-type:personal-reply; font-family:"Aptos",sans-serif; color:windowtext;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt; mso-ligatures:none;} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} /* List Definitions */ @list l0 {mso-list-id:264584430; mso-list-template-ids:1558597162;} @list l0:level1 {mso-level-number-format:bullet; mso-level-text:=EF=82=B7; mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Symbol;} @list l0:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:1.0in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:"Courier New"; mso-bidi-font-family:"Times New Roman";} @list l0:level3 {mso-level-number-format:bullet; mso-level-text:=EF=82=A7; mso-level-tab-stop:1.5in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level4 {mso-level-number-format:bullet; mso-level-text:=EF=82=A7; mso-level-tab-stop:2.0in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level5 {mso-level-number-format:bullet; mso-level-text:=EF=82=A7; mso-level-tab-stop:2.5in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level6 {mso-level-number-format:bullet; mso-level-text:=EF=82=A7; mso-level-tab-stop:3.0in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level7 {mso-level-number-format:bullet; mso-level-text:=EF=82=A7; mso-level-tab-stop:3.5in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level8 {mso-level-number-format:bullet; mso-level-text:=EF=82=A7; mso-level-tab-stop:4.0in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level9 {mso-level-number-format:bullet; mso-level-text:=EF=82=A7; mso-level-tab-stop:4.5in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} ol {margin-bottom:0in;} ul {margin-bottom:0in;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--></head><body lang=3DEN-US = link=3D"#467886" vlink=3D"#96607D" style=3D'word-wrap:break-word'><div = class=3DWordSection1><p class=3DMsoNormal>There is no way to download a = pre-packaged, out-of-the-box ruleset tailored perfectly to a specific = environment right from the start.<o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>While the = Talos Subscriber ruleset gives you rapid, premium threat updates, even = those rules default primarily to alert actions. This is intentional; if = a ruleset dropped traffic by default, it would instantly break = legitimate services on a home network the moment a false positive = triggered.<o:p></o:p></p><p class=3DMsoNormal><o:p> </o:p></p><p = class=3DMsoNormal>PulledPork is exactly the tool you need to change this = behavior, but its base policies (Connectivity, Balanced, and Security) = are only the starting point. To move from passive alerts to active = blocking (drop actions), you need to configure PulledPork to rewrite the = rule states for you.<o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>Building a = custom ruleset that matches your specific network profile will take a = little work, but here is the general approach to get you = started:<o:p></o:p></p><p = class=3DMsoNormal><b><o:p> </o:p></b></p><p class=3DMsoNormal><b>1. = Enable Inline Dropping in Snort<o:p></o:p></b></p><p = class=3DMsoNormal>First, make sure Snort is actually configured to drop = traffic. If Snort isn't running in inline mode (using DAQ modules like = afpacket or nfq), changing the rules to drop won't do = anything=E2=80=94it will still only log an alert. you need to ensure = your execution mode supports blocking.<o:p></o:p></p><p = class=3DMsoNormal><b><o:p> </o:p></b></p><p class=3DMsoNormal><b>2. = Leverage PulledPork's Modification Files<o:p></o:p></b></p><p = class=3DMsoNormal>Instead of editing the massive ruleset manually every = day (which gets overwritten on every update), you use = PulledPork=E2=80=99s built-in state modification files: dropsid.conf, = enablesid.conf, and disablesid.conf.<o:p></o:p></p><ul = style=3D'margin-top:0in' type=3Ddisc><li class=3DMsoNormal = style=3D'mso-list:l0 level1 lfo1'><b>dropsid.conf</b>: You can add = specific Signature IDs (SIDs) or entire rule categories here. PulledPork = will automatically change the action from alert to drop every time it = downloads a new update.<o:p></o:p></li><li class=3DMsoNormal = style=3D'mso-list:l0 level1 lfo1'><b>disablesid.conf</b>: Use this to = turn off noisy or irrelevant rules (like specific server vulnerabilities = if you aren't running those servers at home) to reduce overhead and = false positives.<o:p></o:p></li></ul><p = class=3DMsoNormal><b><o:p> </o:p></b></p><p class=3DMsoNormal><b>3. = Start Small and Tune<o:p></o:p></b></p><p class=3DMsoNormal>Start by = using dropsid.conf on highly reliable, high-severity categories (like = known malware command-and-control communication or active exploits). = Watch your logs closely for a week to catch false positives before = expanding your drop list.<o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>Tailoring a = ruleset is an iterative process, but utilizing PulledPork to manage the = rule modifications is the standard, efficient way to handle = it.<o:p></o:p></p><p class=3DMsoNormal><o:p> </o:p></p><div><p = class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'>WINSNORT.com = Management=E2=80=A6<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'>--<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'>******************** Established = ~ 2003 **********************<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'>* FREE Windows Intrusion = Detection System (WinIDS) Tutorials *<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'>*=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 ~~ FREE Windows Support Forums = ~~=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0 *<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'>*=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 Visit @ = http://winsnort.com=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 = *<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'>*=C2=A0=C2=A0=C2=A0=C2=A0 Snort: = Open Source Network IDS - http://snort.org=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 = *<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'>**********************************= ****************************<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'>Best = regards,<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Courier = New";mso-ligatures:standardcontextual'>Michael...<o:p></o:p></span></p></= div><p class=3DMsoNormal><o:p> </o:p></p><div><div = style=3D'border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in = 0in 0in'><p class=3DMsoNormal><b><span = style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif'>From:</span><= /b><span style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif'> = Snort-users <[email protected]> <b>On Behalf Of = </b>Jonathan Lee via Snort-users<br><b>Sent:</b> Thursday, June 18, 2026 = 12:07 PM<br><b>To:</b> Peter Lyons = <[email protected]><br><b>Cc:</b> = [email protected]<br><b>Subject:</b> Re: [Snort-users] Ruleset = advice for beginners<o:p></o:p></span></p></div></div><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>You have to = set block on alert and inline mode or legacy = mode <o:p></o:p></p><div><p class=3DMsoNormal>Sent from my = iPhone<o:p></o:p></p></div><div><p = class=3DMsoNormal><br><br><o:p></o:p></p><blockquote = style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><p class=3DMsoNormal = style=3D'margin-bottom:12.0pt'>On Jun 18, 2026, at 08:50, Peter Lyons = via Snort-users <<a = href=3D"mailto:[email protected]">[email protected]</= a>> wrote:<o:p></o:p></p></blockquote></div><blockquote = style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p = class=3DMsoNormal><span = style=3D'font-family:"Tahoma",sans-serif'>=EF=BB=BF</span> = <o:p></o:p></p><p style=3D'margin-bottom:0in'>About a year ago I = installed snort3 and pulledpork on ubuntu 24.04 to provide better = protection on my home network.<o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>I registered and used the LightSPD_ruleset, = rule_mode=3Dsimple, ips_policy=3Dbalanced<o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>Got it all working, and auto updating the = LightSPD ruleset everyday.<o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>At the start, I was checking the log $ tail = -f /var/snort/alert_json.txt to see if it was working.<o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>So I felt very happy and = secure.<o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>Then the other day I checked the log file a = bit more and noticed the log file only had <b>alert warnings</b> and no = rule actions like block or drop etc.<o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>So then I checked the LightSPD_ruleset and = noticed that by default the rule actions are all set to <b>alert = warnings.</b><o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>Which means I have to monitor the log file = and customize the rules myself.<o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>While I=E2=80=99d call myself a linux = enthusiast, I don=E2=80=99t have the expertise to do = that.<o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'><b>Is there a way to get a rule set suitable = for a home network?</b><o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>I=E2=80=99m thinking there might be a = community rule set suitable or pay for a subscribed Talos = ruleset.<o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>I=E2=80=99m assuming the subscribed ruleset = comes with rule actions to provide protection, and instant threat = updates.<o:p></o:p></p><p style=3D'margin-bottom:0in'>Are my options = correct? <o:p></o:p></p><p = style=3D'margin-bottom:0in'><o:p> </o:p></p><p = style=3D'margin-bottom:0in'>Advise please.<o:p></o:p></p><p>PS: I am new = to this mailing list.<o:p></o:p></p><p>Peter = Lyons<o:p></o:p></p><p><o:p> </o:p></p><p = class=3DMsoNormal>_______________________________________________<br>Snor= t-users mailing list<br><a = href=3D"mailto:[email protected]">[email protected]</= a><br>Go to this URL to change user options or unsubscribe:<br><a = href=3D"https://lists.snort.org/mailman/listinfo/snort-users">https://lis= ts.snort.org/mailman/listinfo/snort-users</a><br><br> To = unsubscribe, send an email to:<br> <a = href=3D"mailto:[email protected]">snort-users-leave@lists= .snort.org</a><br><br>Please visit <a = href=3D"http://blog.snort.org">http://blog.snort.org</a> to stay current = on all the latest Snort news!<br><br>Please follow these rules: <a = href=3D"https://snort.org/faq/what-is-the-mailing-list-etiquette">https:/= /snort.org/faq/what-is-the-mailing-list-etiquette</a><o:p></o:p></p></div= ></blockquote></div></body></html> ------=_NextPart_000_0008_01DD0243.9D251360-- --===============7118152410918930080== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============7118152410918930080==--