- 
                Notifications
    You must be signed in to change notification settings 
- Fork 524
Rules
Please note! This wiki is no longer maintained. Our documentation has moved to https://securityonion.net/docs/. Please update your bookmarks. You can find the latest version of this page at: https://securityonion.net/docs/Rules.
Rulesets are chosen during setup and are specified in /etc/nsm/pulledpork/pulledpork.conf.
If you change the the configuration in pulledpork.conf, then you will need to run rule-update (if in a server/sensor deployment, run rule-update on the master first, then the sensor, or wait for it to be replicated).
Security Onion offers the following choices for rulesets to be used by Snort/Suricata:
- 
ET Open - optimized for Suricata, but available for Snort as well
- free
 For more information, see: 
 https://rules.emergingthreats.net/open/
- 
ET Pro (Proofpoint) - optimized for Suricata, but available for Snort as well
- rules retrievable as released
- license fee per sensor
 For more information, see: 
 https://www.proofpoint.com/us/threat-insight/et-pro-ruleset
- 
Snort Community - optimized for Snort
- community-contributed rules
- free
 For more information, see: 
 https://www.snort.org/downloads/#rule-downloads
 https://www.snort.org/faq/what-are-community-rules
- 
Snort Registered - optimized for Snort
- Snort SO (Shared Object) rules will only work with Snort
- same rules as Snort Subscriber ruleset, except rules only retrievable after 30 days past release
- free
 For more information, see: 
 https://www.snort.org/downloads/#rule-downloads
 https://snort.org/documents/registered-vs-subscriber
- 
Snort Subscriber (Talos) - optimized for Snort
- Snort SO (Shared Object) rules will only work with Snort
- rules retrievable as released
- license fee per sensor
 For more information, see: 
 https://www.snort.org/downloads/#rule-downloads
 https://snort.org/documents/registered-vs-subscriber
- Introduction
- Use Cases
- Hardware Requirements
- Release Notes
- Download/Install
- Booting Issues
- After Installation
- UTC and Time Zones
- Services
- VirtualBox Walkthrough
- VMWare Walkthrough
- Videos
- Architecture
- Cheat Sheet
- Conference
- Elastic Stack
- Elastic Architecture
- Elasticsearch
- Logstash
- Kibana
- ElastAlert
- Curator
- FreqServer
- DomainStats
- Docker
- Redis
- Data Fields
- Beats
- Pre-Releases
- ELSA to Elastic
- Network Configuration
- Proxy Configuration
- Firewall/Hardening
- Email Configuration
- Integrating with other systems
- Changing IP Addresses
- NTP
- Managing Alerts
- Managing Rules
- Adding Local Rules
- Disabling Processes
- Filtering with BPF
- Adjusting PF_RING for traffic
- MySQL Tuning
- Adding a new disk
- High Performance Tuning
- Trimming PCAPs