Sign inSign up

jgru/snort3

By jgru

•Updated about 4 years ago

Image
0

903

jgru/snort3 repository overview

⁠Table of Contents

  1. Motivation⁠
  2. Usage⁠
    1. Simple Usage via Shell Function⁠
    2. Elaborated Usage Via docker-compose⁠
  3. Acknowledgements⁠

This is a dockerized setup of snort3. It is geared toward checking a directory of .pcap-files but can be used for "online-mode" as well.

⁠Motivation

There is a docker container with snort3⁠ provided by "Cisco Talos", which is intended for interactive use. However, the source Dockerfile is not available; therefore, I decided to craft my own version, which is geared and configured toward my personal use cases.

⁠Usage

⁠Simple Usage via Shell Function

It is rather convenient to declare a shell function inside your favorite shell (.bashrc or .zshrc) to run the dockerized snort3.

function snort () {
    docker run -it --rm --net=host -v $(pwd):/tmp \
                 snort3 snort -c /etc/snort/snort.lua -k none -l /tmp/ $@;
    sudo chmod 644 alert*.txt
}

Here, we bind-mount the current working directory into the container and define some rudimentary configuration for snort. The chmod-command in the function definition ensures that the resulting logs files are readable for an unpriviledged user.

Note that this approach necessitates that the rules (an eventually the .pcap-files to analyze) are present in the current working directory's.

To run it, just call it like so

snort -R /tmp/snort.rules -r /tmp/test.pcap

If you want to run it in online-mode just use the following command:

# Retrieve NIC to capture on
NIC=$(ip -j a show \
    | jq '.[] | .addr_info | .[] | select(.scope == "global") | .label ' \
        | grep "wlp" |  sed 's/"//g')

# Run snort
snort -R /tmp/snort.rules -i $NIC

⁠Elaborated Usage Via docker-compose

If you prefer a more static setup and just want to check .pcap-files, placed in the sub-directory ./pcaps using some Snort-rules placed in ./etc/rules/snort.rules, then run:

docker-compose up

This will append the arguments in the command-field of the docker-compose.yml to the entrypoint specified in there.

Alternatively, you could use, the docker-compose run-command naming the service to pass custom options to the entrypoint to achieve the same:

docker-compose run snort3 -r test.pcap

Note that the .pcap-files are expected to live in the a/m sub-directory.

To run snort3 in continuos online mode, run the following command.

NIC="eth0" # or another NIC available on the host machine
docker-compose run snort3 -i ${NIC}

⁠Acknowledgements

The Dockerfile is inspired by https://github.com/John-Lin/docker-snort⁠.

Tag summary

Content type

Image

Digest

sha256:a318b42b7…

Size

667.8 MB

Last updated

about 4 years ago

docker pull jgru/snort3