Snort Intrusion Detection, Rule Writing, and PCAP Analysis (Udemy.com)

Learn how to write Snort rules from a real cybersecurity professional with lectures and hands-on lab exercises.

Created by: Jesse Kurrus, M.S., OSCP, CEH, Security+, Linux+, Network+, CISSP

Produced in 2021

icon
What you will learn

  • Write Snort Rules
  • Analyze PCAPS using Wireshark and Tcpdump
  • Create Virtual Machines using VirtualBox
  • Configure Security Onion
  • Test Snort rules using automated scripts
  • Analyze Snort NIDS alerts using Squert
  • Configure Kali Linux
  • Test exploits and analyze resulting network traffic

icon
Quality Score

Content Quality
/
Video Quality
/
Qualified Instructor
/
Course Pace
/
Course Depth & Coverage
/

Overall Score : 90 / 100

icon
Course Description

Hello everybody. My name is Jesse Kurrus, and Ill be your professor for the duration of the Snort Intrusion Detection, Rule Writing, and PCAP Analysis course. This course will consist of written material to go over on your own pace, andlabsto reinforce the conceptsfrom the provided resources.
To follow along with these labs, you'll need a VirtualBox, Security Onion,Kali Linux, and Windows 7 VMs. These are all free and open source, including the Windows 7 VMwhich is available freefor development purposes.

This course is 100%hands-on, save for the initial introduction.
Please be prepared to follow along with these labs.

The following are the hands-on labs.
Please refer to the course for full descriptions:

Lab 1: Setting up Security Onion with VirtualBoxLab 2: Boleto Malware Snort Rule Writing and PCAP AnalysisLab 3: Vetting Snort Rule Quality with DumbpigLab 4:
Utilizing Offset and Depth in a Snort RuleLab 5: Kali Linux Setup with VirtualBoxLab 6: Snort Rule Writing (SSH and FTP)Lab 7: Windows 7 Eternalblue Vulnerable VM VirtualBox SetupLab 8: Windows 7 Eternalblue Exploitation and Snort/PCAP AnalysisLab 9: Eternalblue PCAP Analysis and Snort Rule WritingLab 10: Ubuntu Server 12.
04 Vulnerable VM VirtualBox SetupLab 11: Ubuntu Server 12.
04 Heartbleed Exploitation and Snort/PCAP AnalysisLab 12: Heartbleed PCAP Analysis and Snort Rule WritingWho this course is for:
Cybersecurity ProfessionalsInformation Security AnalystsNetwork Security AnalystsSOC AnalystsCybersecurity Students

icon
Instructor Details

Summary: Jesse Kurrus is a cybersecurity expert with a breadth and depth of knowledge, professional experience, and top of the line credentials directly related to his field of expertise. He has provided quality training for thousands of students online, has mentored them one-on-one, and has coached many to acquire jobs in the cyber field. Professional strengths include security analysis, intrusion detection, ethical hacking, penetration testing, training, and technical writing. Jesse has a true passion for cybersecurity and information technology, and an insatiable ambition to further his knowledge and professional skill set.

Specialties: Intrusion Detection / Network Security Monitoring (Security Onion, Snort, Bro, and Suricata); SIEM Technology (Elasticsearch, Logstash, Kibana (ELK), ArcSight, and Splunk); PCAP analysis (Tcpdump, Wireshark, NetworkMiner, NetWitness/Security Analytics); Penetration Testing (Kali Linux, BurpSuite, Nikto, Nmap, Metasploit, etc.)
Current Degrees/Certifications: M.S. in Information Technology with Information Assurance Specialization / B.S. in Computer Networks and Security / Network+, A+, Security+, Linux+, Certified Ethical Hacker v8 (CEH), Offensive Security Certified Professional (OSCP), Certified Information Systems Security Professional (CISSP), eLearnSecurity Web applicationPenetration Tester (eWPT)

icon
Reviews

4.5

119 total reviews

5 star 4 star 3 star 2 star 1 star
% Complete
% Complete
% Complete
% Complete
% Complete

By Nguyen The Minh on 11/22/2020

Not for beginner

By TheCorei71 on 11/8/2020

Did not explain the components of the rules, their purpose, order, and things that usually go wrong during rule writing. Was expecting to see some comparison with suricata rule structure, also some info around ET pro ruleset, Talos rule set etc. A section for the basics would make this course close to complete.

By Ciaran McGlynn on 11/8/2020

Course was good and delivered what it said it would - steps were easy to follow and could be replicated. Instructor is clear and knowledgeable. I would have liked some next steps as I feel I have just got started and I'm not sure what to do next.

By Aleksandra Kusiak on 10/9/2020

ok

By EA on 9/14/2020

Good for intermediate.

By Wojciech Matysiak on 9/7/2020

Great course. In my opinion the biggest advantage is showing everything from scratch - even vm image installation is not skipped. The only thing I could be changed is ordering - before writing multiline rules it would be good to explain basic structure of snort rule. Without this there may be a little confusion in the beginning.

By Christof Jahns on 9/5/2020

Great!

By Daniel Lissett on 8/19/2020

Maybe go a little slower in pace and speech for those of trying to get up to speed or new to networks? Otherwise great. Excellent to see step by step instructions and clear screen views.

By Mike Emerson on 8/9/2020

This is like studying in an encyclopedia. No instructions, no explanations, just rambling the detail of each command. Need to EXPLAIN these things and not just ramble ever onward.

By Damian Cleary on 8/4/2020

It was a fascinating first look at Snort and Security Onion. Instructor moved very quickly and I could have used more information about the syntax of Snort rule writing.

By Michael Coetzee on 7/26/2020

Lacks Content and detailed explanation of Snort Rule Structure. Could go a lot more in Depth .

By Michael Campbell on 7/22/2020

Not so much a snort tutorial as a demonstration, but gives some things to go research on my own. The security onion setup was nice though; had never used it before.