Re: Ruleset advice for beginners

Michael Steele via Snort-users <[email protected]> Mon, 22 Jun 2026 16:35:30 +0000 (UTC)
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
This is a multipart message in MIME format.

--===============7118152410918930080==
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0008_01DD0243.9D251360"
Content-Language: en-us

This is a multipart message in MIME format.

------=_NextPart_000_0008_01DD0243.9D251360
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

There is no way to download a pre-packaged, out-of-the-box ruleset =
tailored perfectly to a specific environment right from the start.

=20

While the Talos Subscriber ruleset gives you rapid, premium threat =
updates, even those rules default primarily to alert actions. This is =
intentional; if a ruleset dropped traffic by default, it would instantly =
break legitimate services on a home network the moment a false positive =
triggered.

=20

PulledPork is exactly the tool you need to change this behavior, but its =
base policies (Connectivity, Balanced, and Security) are only the =
starting point. To move from passive alerts to active blocking (drop =
actions), you need to configure PulledPork to rewrite the rule states =
for you.

=20

Building a custom ruleset that matches your specific network profile =
will take a little work, but here is the general approach to get you =
started:

=20

1. Enable Inline Dropping in Snort

First, make sure Snort is actually configured to drop traffic. If Snort =
isn't running in inline mode (using DAQ modules like afpacket or nfq), =
changing the rules to drop won't do anything=E2=80=94it will still only =
log an alert. you need to ensure your execution mode supports blocking.

=20

2. Leverage PulledPork's Modification Files

Instead of editing the massive ruleset manually every day (which gets =
overwritten on every update), you use PulledPork=E2=80=99s built-in =
state modification files: dropsid.conf, enablesid.conf, and =
disablesid.conf.

*	dropsid.conf: You can add specific Signature IDs (SIDs) or entire rule =
categories here. PulledPork will automatically change the action from =
alert to drop every time it downloads a new update.
*	disablesid.conf: Use this to turn off noisy or irrelevant rules (like =
specific server vulnerabilities if you aren't running those servers at =
home) to reduce overhead and false positives.

=20

3. Start Small and Tune

Start by using dropsid.conf on highly reliable, high-severity categories =
(like known malware command-and-control communication or active =
exploits). Watch your logs closely for a week to catch false positives =
before expanding your drop list.

=20

Tailoring a ruleset is an iterative process, but utilizing PulledPork to =
manage the rule modifications is the standard, efficient way to handle =
it.

=20

WINSNORT.com Management=E2=80=A6

--

******************** Established ~ 2003 **********************

* FREE Windows Intrusion Detection System (WinIDS) Tutorials *

*            ~~ FREE Windows Support Forums ~~               *

*               Visit @ http://winsnort.com                  *

*     Snort: Open Source Network IDS - http://snort.org      *

**************************************************************

=20

Best regards,

Michael...

=20

From: Snort-users <[email protected]> On Behalf Of =
Jonathan Lee via Snort-users
Sent: Thursday, June 18, 2026 12:07 PM
To: Peter Lyons <[email protected]>
Cc: [email protected]
Subject: Re: [Snort-users] Ruleset advice for beginners

=20

You have to set block on alert and inline mode or legacy mode=20

Sent from my iPhone





On Jun 18, 2026, at 08:50, Peter Lyons via Snort-users =
<[email protected] <mailto:[email protected]> > =
wrote:

=EF=BB=BF=20

About a year ago I installed snort3 and pulledpork on ubuntu 24.04 to =
provide better protection on my home network.

=20

I registered and used the LightSPD_ruleset, rule_mode=3Dsimple, =
ips_policy=3Dbalanced

=20

Got it all working, and auto updating the LightSPD ruleset everyday.

=20

At the start, I was checking the log $ tail -f /var/snort/alert_json.txt =
to see if it was working.

=20

So I felt very happy and secure.

=20

Then the other day I checked the log file a bit more and noticed the log =
file only had alert warnings and no rule actions like block or drop etc.

=20

So then I checked the LightSPD_ruleset and noticed that by default the =
rule actions are all set to alert warnings.

=20

Which means I have to monitor the log file and customize the rules =
myself.

=20

While I=E2=80=99d call myself a linux enthusiast, I don=E2=80=99t have =
the expertise to do that.

=20

Is there a way to get a rule set suitable for a home network?

=20

I=E2=80=99m thinking there might be a community rule set suitable or pay =
for a subscribed Talos ruleset.

=20

I=E2=80=99m assuming the subscribed ruleset comes with rule actions to =
provide protection, and instant threat updates.

Are my options correct?=20

=20

Advise please.

PS: I am new to this mailing list.

Peter Lyons

=20

_______________________________________________
Snort-users mailing list
[email protected] <mailto:[email protected]>=20
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

   To unsubscribe, send an email to:
   [email protected] =
<mailto:[email protected]>=20

Please visit http://blog.snort.org to stay current on all the latest =
Snort news!

Please follow these rules: =
https://snort.org/faq/what-is-the-mailing-list-etiquette


------=_NextPart_000_0008_01DD0243.9D251360
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered =
medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Aptos;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	font-size:12.0pt;
	font-family:"Aptos",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#467886;
	text-decoration:underline;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Aptos",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	mso-ligatures:none;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:264584430;
	mso-list-template-ids:1558597162;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:=EF=82=B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:=EF=82=A7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:=EF=82=A7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:=EF=82=A7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:=EF=82=A7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:=EF=82=A7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:=EF=82=A7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:=EF=82=A7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US =
link=3D"#467886" vlink=3D"#96607D" style=3D'word-wrap:break-word'><div =
class=3DWordSection1><p class=3DMsoNormal>There is no way to download a =
pre-packaged, out-of-the-box ruleset tailored perfectly to a specific =
environment right from the start.<o:p></o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>While the =
Talos Subscriber ruleset gives you rapid, premium threat updates, even =
those rules default primarily to alert actions. This is intentional; if =
a ruleset dropped traffic by default, it would instantly break =
legitimate services on a home network the moment a false positive =
triggered.<o:p></o:p></p><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>PulledPork is exactly the tool you need to change this =
behavior, but its base policies (Connectivity, Balanced, and Security) =
are only the starting point. To move from passive alerts to active =
blocking (drop actions), you need to configure PulledPork to rewrite the =
rule states for you.<o:p></o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>Building a =
custom ruleset that matches your specific network profile will take a =
little work, but here is the general approach to get you =
started:<o:p></o:p></p><p =
class=3DMsoNormal><b><o:p>&nbsp;</o:p></b></p><p class=3DMsoNormal><b>1. =
Enable Inline Dropping in Snort<o:p></o:p></b></p><p =
class=3DMsoNormal>First, make sure Snort is actually configured to drop =
traffic. If Snort isn't running in inline mode (using DAQ modules like =
afpacket or nfq), changing the rules to drop won't do =
anything=E2=80=94it will still only log an alert. you need to ensure =
your execution mode supports blocking.<o:p></o:p></p><p =
class=3DMsoNormal><b><o:p>&nbsp;</o:p></b></p><p class=3DMsoNormal><b>2. =
Leverage PulledPork's Modification Files<o:p></o:p></b></p><p =
class=3DMsoNormal>Instead of editing the massive ruleset manually every =
day (which gets overwritten on every update), you use =
PulledPork=E2=80=99s built-in state modification files: dropsid.conf, =
enablesid.conf, and disablesid.conf.<o:p></o:p></p><ul =
style=3D'margin-top:0in' type=3Ddisc><li class=3DMsoNormal =
style=3D'mso-list:l0 level1 lfo1'><b>dropsid.conf</b>: You can add =
specific Signature IDs (SIDs) or entire rule categories here. PulledPork =
will automatically change the action from alert to drop every time it =
downloads a new update.<o:p></o:p></li><li class=3DMsoNormal =
style=3D'mso-list:l0 level1 lfo1'><b>disablesid.conf</b>: Use this to =
turn off noisy or irrelevant rules (like specific server vulnerabilities =
if you aren't running those servers at home) to reduce overhead and =
false positives.<o:p></o:p></li></ul><p =
class=3DMsoNormal><b><o:p>&nbsp;</o:p></b></p><p class=3DMsoNormal><b>3. =
Start Small and Tune<o:p></o:p></b></p><p class=3DMsoNormal>Start by =
using dropsid.conf on highly reliable, high-severity categories (like =
known malware command-and-control communication or active exploits). =
Watch your logs closely for a week to catch false positives before =
expanding your drop list.<o:p></o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>Tailoring a =
ruleset is an iterative process, but utilizing PulledPork to manage the =
rule modifications is the standard, efficient way to handle =
it.<o:p></o:p></p><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'>WINSNORT.com =
Management=E2=80=A6<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'>--<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'>******************** Established =
~ 2003 **********************<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'>* FREE Windows Intrusion =
Detection System (WinIDS) Tutorials *<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'>*=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 ~~ FREE Windows Support Forums =
~~=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0 *<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'>*=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 Visit @ =
http://winsnort.com=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 =
*<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'>*=C2=A0=C2=A0=C2=A0=C2=A0 Snort: =
Open Source Network IDS - http://snort.org=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 =
*<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'>**********************************=
****************************<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'>Best =
regards,<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Courier =
New";mso-ligatures:standardcontextual'>Michael...<o:p></o:p></span></p></=
div><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><div =
style=3D'border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif'>From:</span><=
/b><span style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif'> =
Snort-users &lt;[email protected]&gt; <b>On Behalf Of =
</b>Jonathan Lee via Snort-users<br><b>Sent:</b> Thursday, June 18, 2026 =
12:07 PM<br><b>To:</b> Peter Lyons =
&lt;[email protected]&gt;<br><b>Cc:</b> =
[email protected]<br><b>Subject:</b> Re: [Snort-users] Ruleset =
advice for beginners<o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>You have to =
set block on alert and inline mode or legacy =
mode&nbsp;<o:p></o:p></p><div><p class=3DMsoNormal>Sent from my =
iPhone<o:p></o:p></p></div><div><p =
class=3DMsoNormal><br><br><o:p></o:p></p><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><p class=3DMsoNormal =
style=3D'margin-bottom:12.0pt'>On Jun 18, 2026, at 08:50, Peter Lyons =
via Snort-users &lt;<a =
href=3D"mailto:[email protected]">[email protected]</=
a>&gt; wrote:<o:p></o:p></p></blockquote></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-family:"Tahoma",sans-serif'>=EF=BB=BF</span> =
<o:p></o:p></p><p style=3D'margin-bottom:0in'>About a year ago I =
installed snort3 and pulledpork on ubuntu 24.04 to provide better =
protection on my home network.<o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>I registered and used the LightSPD_ruleset, =
rule_mode=3Dsimple, ips_policy=3Dbalanced<o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>Got it all working, and auto updating the =
LightSPD ruleset everyday.<o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>At the start, I was checking the log $ tail =
-f /var/snort/alert_json.txt to see if it was working.<o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>So I felt very happy and =
secure.<o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>Then the other day I checked the log file a =
bit more and noticed the log file only had <b>alert warnings</b> and no =
rule actions like block or drop etc.<o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>So then I checked the LightSPD_ruleset and =
noticed that by default the rule actions are all set to <b>alert =
warnings.</b><o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>Which means I have to monitor the log file =
and customize the rules myself.<o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>While I=E2=80=99d call myself a linux =
enthusiast, I don=E2=80=99t have the expertise to do =
that.<o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'><b>Is there a way to get a rule set suitable =
for a home network?</b><o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>I=E2=80=99m thinking there might be a =
community rule set suitable or pay for a subscribed Talos =
ruleset.<o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>I=E2=80=99m assuming the subscribed ruleset =
comes with rule actions to provide protection, and instant threat =
updates.<o:p></o:p></p><p style=3D'margin-bottom:0in'>Are my options =
correct? <o:p></o:p></p><p =
style=3D'margin-bottom:0in'><o:p>&nbsp;</o:p></p><p =
style=3D'margin-bottom:0in'>Advise please.<o:p></o:p></p><p>PS: I am new =
to this mailing list.<o:p></o:p></p><p>Peter =
Lyons<o:p></o:p></p><p><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>_______________________________________________<br>Snor=
t-users mailing list<br><a =
href=3D"mailto:[email protected]">[email protected]</=
a><br>Go to this URL to change user options or unsubscribe:<br><a =
href=3D"https://lists.snort.org/mailman/listinfo/snort-users">https://lis=
ts.snort.org/mailman/listinfo/snort-users</a><br><br>&nbsp; &nbsp;To =
unsubscribe, send an email to:<br>&nbsp; &nbsp;<a =
href=3D"mailto:[email protected]">snort-users-leave@lists=
.snort.org</a><br><br>Please visit <a =
href=3D"http://blog.snort.org">http://blog.snort.org</a> to stay current =
on all the latest Snort news!<br><br>Please follow these rules: <a =
href=3D"https://snort.org/faq/what-is-the-mailing-list-etiquette">https:/=
/snort.org/faq/what-is-the-mailing-list-etiquette</a><o:p></o:p></p></div=
></blockquote></div></body></html>
------=_NextPart_000_0008_01DD0243.9D251360--


--===============7118152410918930080==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============7118152410918930080==--