Cybersecurity Project: How To Install an IDS (Snort)

Поделиться
HTML-код
  • Опубликовано: 14 дек 2024

Комментарии • 62

  • @TheChemistDIY
    @TheChemistDIY 7 месяцев назад +4

    There's not enough Snort tutorials on YT, thanks for putting this out there.
    I would love to see a live demo of an attack taking place (real time) and the IDS/IPS vm capturing this as it goes down.

    • @MyDFIR
      @MyDFIR  7 месяцев назад +1

      That is a fantastic idea ❤️

  • @joshuaspeshock4636
    @joshuaspeshock4636 Год назад +2

    Amazing walkthrough from start to finish. Thank you for providing the documentation my man to follow along and ending the video with ideas to add onto this and expand but asking questions on what content we would like to see and the enthusiasm to create it. Hands down the cybersecurity community is very thankful to have you and as always thank you so much for what you do for the community and looking forward to more technical tool and scenario walkthroughs like these and more to come great work!

    • @MyDFIR
      @MyDFIR  Год назад +1

      Thanks Joshua! More to come for sure ❤️

  • @kd2yxs
    @kd2yxs 26 дней назад

    Best instruction video on snort3. Thanks!

    • @MyDFIR
      @MyDFIR  26 дней назад

      Wow, thanks!

  • @olayinkaojo8828
    @olayinkaojo8828 5 месяцев назад

    Hi MyDFIR. This tutorial is a master class, especially for Snort 3! Simple, straight forward, and strong. Thanks

    • @MyDFIR
      @MyDFIR  5 месяцев назад

      Thank you for watching ❤️

  • @lennartschneider1710
    @lennartschneider1710 6 месяцев назад +1

    Thanks to your video I was able to finish my assignment on snort! 😭

    • @MyDFIR
      @MyDFIR  6 месяцев назад

      Nice!

  • @fredokaych
    @fredokaych 6 месяцев назад +2

    This is great. Could you be kind enough to prepare another video on Snort 3 IPS, especially using NFQUEUE?

  • @TheSilentLearner786
    @TheSilentLearner786 Год назад +3

    Sir , defenetly we need the splunk tutorial this is so special❤

    • @MyDFIR
      @MyDFIR  Год назад

      👀 thanks for watching!

  • @gmontenegro9711
    @gmontenegro9711 Год назад +1

    Sweet this is great content!

    • @MyDFIR
      @MyDFIR  Год назад

      Glad you enjoy it!

  • @claudiotonelli7709
    @claudiotonelli7709 6 месяцев назад +1

    Compliment!!! Very good video!!

    • @MyDFIR
      @MyDFIR  6 месяцев назад

      Thank you very much!

  • @oscarmarcos1217
    @oscarmarcos1217 Месяц назад

    how can i get back my eneric-receive-offload and large-receive-offload switch on again???

  • @rockycool222
    @rockycool222 3 месяца назад

    Can you please make a video to integrate snort v3 to splunk as well .... thank you

  • @olayinkaojo8828
    @olayinkaojo8828 4 месяца назад

    Please can you provide a guide on setting rules to detect and prevent DDoS and Sql injection attacks, and storing the alert in CSV file? Thanks

  • @sertac5262
    @sertac5262 3 месяца назад

    Hello, first of all, thank you for the video; it was very helpful for me. I would like to take the output from Snort and save it in JSON format. Could you please guide me on how to do this? Thank you in advance.

  • @batista98854
    @batista98854 Год назад

    Thanks from India.

    • @MyDFIR
      @MyDFIR  Год назад +1

      Thanks for watching!

  • @toasanseun470
    @toasanseun470 2 месяца назад

    very detailed

    • @MyDFIR
      @MyDFIR  2 месяца назад

      Glad you think so!

  • @henry-c8o
    @henry-c8o Год назад +1

    im down for fowarding the logs into splunk / digest it into splunk super cool!

    • @infosecvolts
      @infosecvolts Год назад

      +1 please make it @MyDFIR

    • @MyDFIR
      @MyDFIR  Год назад

      👀👀 Thanks for watching!!

  • @Thubbie02
    @Thubbie02 24 дня назад

    i am having issues with the unzip pcap password, i typed infected but its not working

    • @Thubbie02
      @Thubbie02 24 дня назад

      it worked, they changed the password "infected _followed by the date"

  • @Javaman92
    @Javaman92 6 месяцев назад

    WOW, you really know your stuff.

    • @MyDFIR
      @MyDFIR  6 месяцев назад +1

      Haha thanks! I know very little still... but I try!

  • @johnvardy9559
    @johnvardy9559 11 месяцев назад

    Which one operation system you used on everyday tasks?

    • @MyDFIR
      @MyDFIR  11 месяцев назад +1

      I use windows 10 for everyday tasks as it just works. If i need linux capabilities ill use WSL for it and lab stuff ill use whatever is needed

  • @vinnys8328
    @vinnys8328 6 месяцев назад

    I cant get snort to create any pcap files any help?

    • @MyDFIR
      @MyDFIR  5 месяцев назад

      Are you listening on the correct interface?

    • @vinnys8328
      @vinnys8328 5 месяцев назад

      @@MyDFIR I have the -i set to my interface so im not sure whats going on

  • @AceS_34
    @AceS_34 6 месяцев назад

    When you mentioned that you are using a ubuntu server, is that also the ubuntu desktop with the graphical design or the server type?

    • @MyDFIR
      @MyDFIR  6 месяцев назад

      Server type, you can use the GUI if you are not comfortable with CLI 👍 That is what I did in the beginning until I quickly realized in the real world, everyone is using CLI which is mainly the reason why I do it this way in my videos.

    • @AceS_34
      @AceS_34 6 месяцев назад

      @@MyDFIR Ah thank you, that explains it.

  • @olayinkaojo8828
    @olayinkaojo8828 5 месяцев назад

    Please can you help me with installing Snort 3 on Ubuntu 24.04. I am currently in the Thesis phase of my study and need Snort. The error am receiving is at the installation of the prerequisite phase. "E: unable to locate package zlib1g-dev" and also libtool and libmnl-dev. Thanks

    • @MyDFIR
      @MyDFIR  5 месяцев назад +1

      Do double check your spelling for those packages

  • @princeVEGE
    @princeVEGE 4 месяца назад

    Do you have use ubuntu distribution or can I use another like kali linux?

    • @MyDFIR
      @MyDFIR  4 месяца назад

      The list of compatible flavors are on their site, I would suggest looking into that to make sure

  • @Jon_Lopez_io
    @Jon_Lopez_io 11 месяцев назад

    Can you make a video in installing OpenVas?

    • @MyDFIR
      @MyDFIR  11 месяцев назад +1

      Great suggestion!

    • @Jon_Lopez_io
      @Jon_Lopez_io 11 месяцев назад

      @@MyDFIRthank you for your knowledge

  • @travislodes5378
    @travislodes5378 Год назад

    Any chance you could update this with an install for kali

    • @freaksnz1
      @freaksnz1 11 месяцев назад

      It will be the same as Ubuntu server uses Debian base os and so does kali

  • @rohithroyal8777
    @rohithroyal8777 Год назад

    Hii MYDFIR
    I have been working in supporting project nearly 2 years.Now I want to shift my career into cybersecurity. Can you suggest which cybesecurity is best I mean cloud security analyst, or network analyst or Soc analyst.plz suggest me...

  • @guerospinoza-qn1rt
    @guerospinoza-qn1rt Год назад

    Hi yeaterday snort worked well ,today i got Analyzer: Failed to start DAQ instance

    • @MyDFIR
      @MyDFIR  Год назад +1

      Services are running? Have you tried restarting? Try to view the logs and see if it tells you why DAQ stopped.

    • @guerospinoza-qn1rt
      @guerospinoza-qn1rt Год назад

      Thank you i will @@MyDFIR

  • @guerospinoza-qn1rt
    @guerospinoza-qn1rt Год назад

    Hi , i am a 63 years old and trying to learn a little bit about cyber , so i'm a newbie in this field, what i'm trying to understand about a snot how is it running ? Why i can't enable it with systemctl systemctl enable snort.service
    Failed to enable unit: Unit file snort.service does not exist? And how to monitor it , or i have to look everytime in snort log , how do i get an alert if something wrong ? Thank you very much.

    • @MyDFIR
      @MyDFIR  Год назад +1

      Welcome! Snort must be installed first before you can enable its service. To monitor the alerts coming in real time, you will need to use another tool such as Splunk to alert you or sguil - hope that helps!

    • @guerospinoza-qn1rt
      @guerospinoza-qn1rt Год назад

      Thank you very much!@@MyDFIR

  • @akashmhetre8732
    @akashmhetre8732 9 месяцев назад

    no alert is generated ..

    • @MyDFIR
      @MyDFIR  9 месяцев назад

      You could try with other PCAPs to test

  • @Surveilancepredators
    @Surveilancepredators Год назад

    Devil.