Sign inSign up

terpz/snort3

By terpz

•Updated about 4 years ago

Run snort3 in a container (listen mode)

Image
1

2.0K

terpz/snort3 repository overview

This will log to stdout, so setup a loggin driver in your docker-compose, fx.:

    logging:
      driver: "syslog"
      options:
        tag: snort
        syslog-address: "udp://Something:514"

Also this will pull the community rules at start/restart

docker run -t --rm --network host -e INTERFACE=ens192 -e HOME_NET=192.168.0.0/21 --cap-add=NET_ADMIN terpz/snort3:latest

or

version: '3'
services:
  snort3:
    network_mode: host
    tty: true
    image: terpz/snort3:latest
    environment:
      - INTERFACE=ens192
      - HOME_NET=192.168.0.0/21
      - IGNORESID=384
      - TZ=Europe/Copenhagen
    cap_add:
      - NET_ADMIN

Example output:

Commencing packet processing
++ [0] ens192
{ "timestamp" : "09/09-11:24:28.102081", "iface" : "ens192", "src_addr" : "192.168.1.150", "dst_addr" : "192.168.4.104", "proto" : "ICMP", "action" : "allow", "msg" : "PROTOCOL-ICMP PING Windows", "priority" : 3, "class" : "Misc activity", "sid" : 382 }
{ "timestamp" : "09/09-11:24:28.102081", "iface" : "ens192", "src_addr" : "192.168.1.150", "dst_addr" : "192.168.4.104", "proto" : "ICMP", "action" : "allow", "msg" : "PROTOCOL-ICMP Unusual PING detected", "priority" : 2, "class" : "Information Leak", "sid" : 29456 }
{ "timestamp" : "09/09-11:24:28.102081", "iface" : "ens192", "src_addr" : "192.168.1.150", "dst_addr" : "192.168.4.104", "proto" : "ICMP", "action" : "allow", "msg" : "PROTOCOL-ICMP PING", "priority" : 3, "class" : "Misc activity", "sid" : 384 }
{ "timestamp" : "09/09-11:24:28.102145", "iface" : "ens192", "src_addr" : "192.168.4.104", "dst_addr" : "192.168.1.150", "proto" : "ICMP", "action" : "allow", "msg" : "PROTOCOL-ICMP Echo Reply", "priority" : 3, "class" : "Misc activity", "sid" : 408 }
{ "timestamp" : "09/09-11:24:39.853044", "iface" : "ens192", "src_addr" : "192.168.1.1", "src_port" : 53, "dst_addr" : "192.168.4.104", "dst_port" : 53336, "proto" : "UDP", "action" : "allow", "msg" : "PROTOCOL-DNS SPOOF query response with TTL of 1 min. and no authority", "priority" : 2, "class" : "Potentially Bad Traffic", "sid" : 254 }
{ "timestamp" : "09/09-11:24:40.338680", "iface" : "ens192", "src_addr" : "192.168.1.1", "src_port" : 53, "dst_addr" : "192.168.4.104", "dst_port" : 34686, "proto" : "UDP", "action" : "allow", "msg" : "PROTOCOL-DNS SPOOF query response with TTL of 1 min. and no authority", "priority" : 2, "class" : "Potentially Bad Traffic", "sid" : 254 }

Based on: https://github.com/jgru/docker-snort3⁠

Tag summary

Content type

Image

Digest

sha256:85b0e36d8…

Size

280.4 MB

Last updated

about 4 years ago

docker pull terpz/snort3