The original open-source IDS (1998!) and still cert-exam canon. If you understand Snort rules, you understand network detection, full stop.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
The 2.9 syntax below is the one exams use.
Sniffer mode first: see what the sensor sees.
-A console prints alerts to screen. Rules file = brain.
proto src sport -> dst dport (options). That simple.
Offline forensics with the same engine.
| -v | sniffer mode |
| -A console | alerts to stdout |
| -c conf | rules/config |
| -r pcap | offline replay |
| -q | quiet |
| sid | signature id |
Rule anatomy (action/proto/addresses/ports/options) = exam + job interview material.
ping sweeps, nmap flags, eternalblue โ write a rule for each; you'll never forget them.
Suricata is the modern multithreaded successor you should also learn.
pulledpork/OSPeting keeps rules fresh in real deployments.
Use Snort only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.