A production-grade IDS/IPS that barks at attack traffic in real time โ point it at your lab and watch your own Nmap scans and Metasploit sessions light up the console.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Emerging Threats Open ruleset ships by default.
eve.json fills with alerts โ the raw material of detection.
fast.log for humans; eve.json for machines/SIEM.
Signatures are just 'if packet looks like X, say Y'. Learn by writing.
From watching (IDS) to stopping (IPS) โ with iptables glue.
| -i iface | live capture |
| -r pcap | analyze offline |
| eve.json | structured output |
| fast.log | human alerts |
| ET Open | free ruleset |
| sid/rev | rule identity/version |
Offline analysis of CyberDefenders pcaps teaches rule logic fast.
MISP + ET rules = free threat-intel-driven detection.
Signature development is a SOC L2 skill โ start day one.
Security Onion bundles Suricata + dashboards if you want the easy mode.
Use Suricata only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.