Snort is the worlds most widely deployed open-source intrusion detection and prevention system, now maintained by Cisco Talos. See features, rulesets, and…
Snort is a network intrusion detection and prevention system that inspects network traffic in real time to identify malicious activity such as exploits, port scans, and known attack signatures. It was created in 1998 by Martin Roesch.
The project became the technical foundation of Sourcefire's commercial security products after Sourcefire was founded in 2001, and in 2009 InfoWorld recognized Snort as one of the greatest pieces of open-source software of all time.
Cisco acquired Sourcefire in 2013 and has continued to develop and maintain Snort through its Cisco Talos threat intelligence group, while keeping the free, open-source core of Snort publicly available under GPLv2.
Snort performs real-time packet analysis and logging on IP networks, using protocol analysis and content pattern matching to detect a wide range of attacks, probes, and exploits.
Snort 3, the current major version, introduces a modernized, multi-threaded architecture designed to improve performance and make rule writing and configuration more flexible compared to the original Snort 2 engine.
Detection relies on Snort rulesets, which come in a free Community tier, a free Registered tier delayed by 30 days, and a paid Subscriber tier that delivers new rules in real time as Cisco Talos publishes them.
The core Snort software engine is completely free and open source under the GNU General Public License version 2, and this has not changed since Cisco's 2013 acquisition of Sourcefire.
Rule access is tiered: the Community Ruleset is free for anyone, the Registered Ruleset is free with a Snort.org account but arrives 30 days after the newest rules, and the Subscriber Ruleset is a paid, real-time rule feed available to Cisco customers and individual subscribers, including discounted personal or home-network pricing.
Exact current Subscriber Ruleset prices are set by Cisco and are not published as a fixed number on the Snort.org site; organizations and individuals sign up directly through Snort.org or Cisco to see applicable rates for their use case.
Yes. The core Snort engine is free and open source under the GNU General Public License version 2, and the Community Ruleset is also free.
Snort is maintained by Cisco, through its Cisco Talos threat intelligence organization, following Cisco's 2013 acquisition of Sourcefire, the company Snort's creator Martin Roesch founded.
Snort 3 is a modernized, multi-threaded rewrite of the original Snort 2 engine, offering improved performance and more flexible rule configuration.
The Community Ruleset is free and community-maintained with Cisco Talos QA, while the paid Subscriber Ruleset delivers new rules in real time as Cisco Talos releases them, ahead of the free Registered tier.
Yes. Snort can operate passively as an intrusion detection system or inline as an intrusion prevention system that actively blocks malicious traffic.
No, the core software does not require a paid license. A paid Subscriber Ruleset is optional and provides faster rule updates.
Snort runs on Linux, Windows, and BSD-based operating systems.
Both are open-source network IDS/IPS engines; Snort is the older, Cisco-maintained project with the largest installed base, while Suricata is a separately developed, natively multi-threaded alternative with its own rule ecosystem.