SSFRULES - Securing Cisco Networks with Snort® Rule Writing Best Practices
5827
SSFRULES - Securing Cisco Networks with Snort® Rule Writing Best Practices
Classroom
Live Virtual
Private/On Site
In this course, you will learn about the key features and characteristics of a typical Snort rule development environment. You will develop and test custom rules in a preinstalled Snort environment and identify how to use advanced rule-writing techniques. You will investigate how to include OpenAppID in your rules and also identify how to filter rules and monitor their performance. This course combines lecture materials and hands-on labs that give you practice in creating Snort rules. This lab-intensive course introduces you to Snort rule writing. Among other powerful features, you become familiar with:
Basic understanding of:
Introduction to Snort Rule Development Snort Rule Syntax and Usage Traffic Flow Through Snort Rules Advanced Rule Options OpenAppID Detection Tuning Snort Lab 1: Connecting to the Lab Environment Lab 2: Introducing Snort Rule Development Lab 3: Basic Rule Syntax and Usage Lab 4: Advanced Rule Options Lab 5: OpenAppID Lab 6: Tuning SnortOutline
Labs
Questions?
Whether you need assistance scheduling a class for yourself or for your group, GCA's Education Account Manager's will craft a customized training solution to meet the needs of your organization.