Skip to content

Latest commit

Β 

History

26 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Snort Custom IDS/IPS Rules

License Snort Platform Status Detection

Snort Custom IDS IPS Rules Banner

πŸ›‘οΈ Snort Custom IDS/IPS Rules

Custom Snort 3 IDS detection rules for detecting reconnaissance, authentication attacks, DNS activity, SMB traffic, policy violations, malware indicators, and data exfiltration. Developed and tested using Snort 3 on Kali Linux.


πŸ“– Overview

Modern enterprise networks face continuous threats from attackers performing reconnaissance, network scanning, authentication attacks, malware deployment, command-and-control communications, and data exfiltration.

This project provides a collection of custom Snort 3 detection rules designed for cybersecurity laboratories and learning environments. The rule set covers reconnaissance detection, authentication attacks, DNS monitoring, SMB activity, data exfiltration indicators, malware-related traffic, and policy violations while demonstrating custom rule development for Snort 3.

It is intended for:

  • SOC Analysts
  • Blue Team Engineers
  • Cybersecurity Students
  • Detection Engineers
  • Network Security Professionals

πŸ›  Technologies

  • Snort 3
  • Kali Linux
  • Git
  • GitHub
  • Bash
  • TCP/IP
  • IDS/IPS

✨ Features

  • TCP SYN Scan Detection
  • TCP FIN Scan Detection
  • TCP NULL Scan Detection
  • TCP XMAS Scan Detection
  • UDP Scan Detection
  • ICMP Flood Detection
  • FTP Brute-Force Detection
  • SSH Brute-Force Detection
  • SMB Activity Detection
  • DNS Monitoring
  • Large HTTP Upload Detection
  • Large File Transfer Detection
  • Malware Indicators
  • Policy Violation Detection

πŸ—οΈ Network Architecture

Traffic is inspected by the Snort Detection Engine using the custom rule set. Matching packets generate alerts that can be reviewed by security analysts or forwarded to SIEM platforms.


πŸ”„ Detection Workflow

The workflow consists of:

  1. Packet Capture
  2. Packet Preprocessing
  3. Rule Matching
  4. Alert Generation
  5. Logging & Analysis

πŸ“‚ Repository Structure

SNORT-CUSTOM-IDS-RULES
β”‚
β”œβ”€β”€ configs
β”‚   └── snort.conf.example
β”‚
β”œβ”€β”€ docs
β”‚   β”œβ”€β”€ Installation.md
β”‚   β”œβ”€β”€ Configuration.md
β”‚   β”œβ”€β”€ Rule-Explanation.md
β”‚   └── Testing.md
β”‚
β”œβ”€β”€ images
β”‚
β”œβ”€β”€ rules
β”‚   └── custom.rules
β”‚
β”œβ”€β”€ scripts
β”‚   β”œβ”€β”€ install.sh
β”‚   β”œβ”€β”€ validate.sh
β”‚   └── run-snort.sh
β”‚
β”œβ”€β”€ test-pcaps
β”‚
β”œβ”€β”€ .gitignore
β”œβ”€β”€ LICENSE
└── README.md

βš™οΈ Requirements

  • Snort 3.x
  • Kali Linux 2025+ (recommended)
  • Root privileges
  • libpcap
  • Network interface in promiscuous mode (for live monitoring)

πŸš€ Installation

Prerequisite: Install Snort 3 before using this rule set. This repository contains only custom detection rules and supporting documentation.

Clone the repository

git clone https://github.com/Swastik-Garg/SNORT-CUSTOM-IDS-RULES.git

cd SNORT-CUSTOM-IDS-RULES

Copy the rule file

sudo cp rules/custom.rules /etc/snort/rules/

Edit the Snort configuration:

sudo nano /etc/snort/snort.lua

Inside the ips section add:

ips =
{
    rules = [[
        include /etc/snort/rules/custom.rules
    ]]
}

βœ… Validate Configuration

sudo snort -T -c /etc/snort/snort.lua

Expected Output

Snort successfully validated the configuration.

▢️ Run Snort

sudo snort \
-c /etc/snort/snort.lua \
-i eth0 \
-A alert_fast

Replace eth0 with your monitoring interface.


πŸ§ͺ Testing Examples

The following examples were used to validate supported detection rules in a controlled laboratory environment.

TCP SYN Scan

sudo nmap -sS <Target-IP>

TCP FIN Scan

sudo nmap -sF <Target-IP>

TCP NULL Scan

sudo nmap -sN <Target-IP>

TCP XMAS Scan

sudo nmap -sX <Target-IP>

ICMP Flood

sudo hping3 --icmp --flood <Target-IP>

OR

ping -f <Target-IP>

FTP Brute Force

hydra -l admin -P rockyou.txt ftp://<Target-IP>

UDP Port Scan

sudo nmap -sU --top-ports 20 <Target-IP>

πŸ“Š Detection Coverage

Attack Detection
TCP SYN Scan βœ…
ICMP Flood βœ…
TCP FIN Scan βœ…
TCP NULL Scan βœ…
TCP XMAS Scan βœ…
UDP Scan βœ…
FTP Brute Force βœ…
SMB Detection βœ…
DNS Tunneling βœ…
Data Exfiltration βœ…

πŸ“ˆ Project Statistics

Metric Value
Snort Version 3.x
Custom Rules 31
Attack Categories 8
Documentation Files 4
Tested Platform Kali Linux
License MIT

πŸ“Έ Demonstration

Snort Startup


TCP SYN Port Scan Detection


TCP FIN Scan Detection


TCP NULL Scan Detection


TCP XMAS Scan Detection


ICMP Flood Detection


FTP Brute Force Detection


UDP Port Scan Detection


πŸ“š Documentation

Complete documentation is available in the docs directory.

File Description
Installation.md Snort Installation Guide
Configuration.md Snort Configuration
Rule-Explanation.md Explanation of every rule
Testing.md Step-by-step testing procedures

πŸ›  Future Improvements

  • Additional malware signatures
  • More reconnaissance detection rules
  • TLS and HTTP protocol inspection
  • PCAP-based automated rule testing
  • GitHub Actions CI validation
  • SIEM integration examples
  • MITRE ATT&CK mapping
  • HTTP inspection enhancements
  • HTTPS/TLS detection
  • SIEM log forwarding examples
  • Docker lab deployment
  • Automated rule testing using GitHub Actions

🀝 Contributing

Contributions are welcome.

  1. Fork this repository.
  2. Create a feature branch.
  3. Commit your changes.
  4. Push your branch.
  5. Open a Pull Request.

⚠️ Disclaimer

These rules are provided for educational purposes and authorized security assessments only.

The author is not responsible for misuse of this project.


πŸ“„ License

This project is licensed under the MIT License.

See the LICENSE file for details.


πŸ§ͺ Lab Environment

The project was developed and validated in a controlled virtual lab.

Component Environment
Host OS Kali Linux
IDS Engine Snort 3
Target Metasploitable 2
Testing Tools Nmap, Hydra, hping3
Virtualization VMware Workstation

🎯 Learning Outcomes

This project demonstrates practical skills in:

  • Network Intrusion Detection
  • Detection Engineering
  • Snort 3 Rule Development
  • Linux System Administration
  • Network Traffic Analysis
  • Cyber Threat Detection
  • Git & GitHub Version Control
  • Security Documentation

πŸ‘¨β€πŸ’» Author

Swastik Garg

B.Tech β€” Internet of Things & Cyber Security

Cybersecurity Enthusiast | Blue Team | SOC | Network Security | Detection Engineering


⭐ If you found this repository useful, please consider giving it a Star.

About

Production-ready custom Snort IDS/IPS rules for detecting reconnaissance, web attacks, brute-force attempts, and network threats.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages