alert icmp any any -> any any (msg:"SURICATA ICMP Ping Detected"; sid:100001;)
alert tcp any any -> any any (flags:S; msg:"SURICATA Nmap SYN Scan Detected"; sid:100002;)
alert icmp any any -> any any (msg:"SNORT ICMP Ping Detected"; sid:110001;)
alert tcp any any -> any any (flags:S; msg:"SNORT Nmap SYN Scan Detected"; sid:110002;)
🔹 실행
sudo snort -A console -q -c /etc/snort/snort.conf -i ens33
📸
🔎 6. 탐지 로그 확인 예시
도구
캡처
Suricata
`tail -f /var/log/suricata/eve.json
Snort
sudo snort -A console -q -c /etc/snort/snort.conf -i ens33