Custom Snort 3 IDS detection rules for detecting reconnaissance, authentication attacks, DNS activity, SMB traffic, policy violations, malware indicators, and data exfiltration. Developed and tested using Snort 3 on Kali Linux.
Modern enterprise networks face continuous threats from attackers performing reconnaissance, network scanning, authentication attacks, malware deployment, command-and-control communications, and data exfiltration.
This project provides a collection of custom Snort 3 detection rules designed for cybersecurity laboratories and learning environments. The rule set covers reconnaissance detection, authentication attacks, DNS monitoring, SMB activity, data exfiltration indicators, malware-related traffic, and policy violations while demonstrating custom rule development for Snort 3.
It is intended for:
- SOC Analysts
- Blue Team Engineers
- Cybersecurity Students
- Detection Engineers
- Network Security Professionals
- Snort 3
- Kali Linux
- Git
- GitHub
- Bash
- TCP/IP
- IDS/IPS
- TCP SYN Scan Detection
- TCP FIN Scan Detection
- TCP NULL Scan Detection
- TCP XMAS Scan Detection
- UDP Scan Detection
- ICMP Flood Detection
- FTP Brute-Force Detection
- SSH Brute-Force Detection
- SMB Activity Detection
- DNS Monitoring
- Large HTTP Upload Detection
- Large File Transfer Detection
- Malware Indicators
- Policy Violation Detection
Traffic is inspected by the Snort Detection Engine using the custom rule set. Matching packets generate alerts that can be reviewed by security analysts or forwarded to SIEM platforms.
The workflow consists of:
- Packet Capture
- Packet Preprocessing
- Rule Matching
- Alert Generation
- Logging & Analysis
SNORT-CUSTOM-IDS-RULES
β
βββ configs
β βββ snort.conf.example
β
βββ docs
β βββ Installation.md
β βββ Configuration.md
β βββ Rule-Explanation.md
β βββ Testing.md
β
βββ images
β
βββ rules
β βββ custom.rules
β
βββ scripts
β βββ install.sh
β βββ validate.sh
β βββ run-snort.sh
β
βββ test-pcaps
β
βββ .gitignore
βββ LICENSE
βββ README.md
- Snort 3.x
- Kali Linux 2025+ (recommended)
- Root privileges
- libpcap
- Network interface in promiscuous mode (for live monitoring)
Prerequisite: Install Snort 3 before using this rule set. This repository contains only custom detection rules and supporting documentation.
Clone the repository
git clone https://github.com/Swastik-Garg/SNORT-CUSTOM-IDS-RULES.git
cd SNORT-CUSTOM-IDS-RULESCopy the rule file
sudo cp rules/custom.rules /etc/snort/rules/Edit the Snort configuration:
sudo nano /etc/snort/snort.luaInside the ips section add:
ips =
{
rules = [[
include /etc/snort/rules/custom.rules
]]
}sudo snort -T -c /etc/snort/snort.luaExpected Output
Snort successfully validated the configuration.
sudo snort \
-c /etc/snort/snort.lua \
-i eth0 \
-A alert_fastReplace eth0 with your monitoring interface.
The following examples were used to validate supported detection rules in a controlled laboratory environment.
sudo nmap -sS <Target-IP>sudo nmap -sF <Target-IP>sudo nmap -sN <Target-IP>sudo nmap -sX <Target-IP>sudo hping3 --icmp --flood <Target-IP>OR
ping -f <Target-IP>hydra -l admin -P rockyou.txt ftp://<Target-IP>sudo nmap -sU --top-ports 20 <Target-IP>| Attack | Detection |
|---|---|
| TCP SYN Scan | β |
| ICMP Flood | β |
| TCP FIN Scan | β |
| TCP NULL Scan | β |
| TCP XMAS Scan | β |
| UDP Scan | β |
| FTP Brute Force | β |
| SMB Detection | β |
| DNS Tunneling | β |
| Data Exfiltration | β |
| Metric | Value |
|---|---|
| Snort Version | 3.x |
| Custom Rules | 31 |
| Attack Categories | 8 |
| Documentation Files | 4 |
| Tested Platform | Kali Linux |
| License | MIT |
Complete documentation is available in the docs directory.
| File | Description |
|---|---|
| Installation.md | Snort Installation Guide |
| Configuration.md | Snort Configuration |
| Rule-Explanation.md | Explanation of every rule |
| Testing.md | Step-by-step testing procedures |
- Additional malware signatures
- More reconnaissance detection rules
- TLS and HTTP protocol inspection
- PCAP-based automated rule testing
- GitHub Actions CI validation
- SIEM integration examples
- MITRE ATT&CK mapping
- HTTP inspection enhancements
- HTTPS/TLS detection
- SIEM log forwarding examples
- Docker lab deployment
- Automated rule testing using GitHub Actions
Contributions are welcome.
- Fork this repository.
- Create a feature branch.
- Commit your changes.
- Push your branch.
- Open a Pull Request.
These rules are provided for educational purposes and authorized security assessments only.
The author is not responsible for misuse of this project.
This project is licensed under the MIT License.
See the LICENSE file for details.
The project was developed and validated in a controlled virtual lab.
| Component | Environment |
|---|---|
| Host OS | Kali Linux |
| IDS Engine | Snort 3 |
| Target | Metasploitable 2 |
| Testing Tools | Nmap, Hydra, hping3 |
| Virtualization | VMware Workstation |
This project demonstrates practical skills in:
- Network Intrusion Detection
- Detection Engineering
- Snort 3 Rule Development
- Linux System Administration
- Network Traffic Analysis
- Cyber Threat Detection
- Git & GitHub Version Control
- Security Documentation
Swastik Garg
B.Tech β Internet of Things & Cyber Security
Cybersecurity Enthusiast | Blue Team | SOC | Network Security | Detection Engineering
β If you found this repository useful, please consider giving it a Star.










