Member-only story
TryHackMe | Snort Challenge — The Basics | WriteUp
Put your snort skills into practice and write snort rules to analyse live capture network traffic
↓↓↓ Click here and earn $5 TryHackMe credit ↓↓↓
Find the room here:
Task 1 Introduction
Read the task above.
No answer needed
Task 2 Writing IDS Rules (HTTP)
Navigate to the task folder.
Use the given pcap file.
Write a single rule to detect “all TCP port 80 traffic” packets in the given pcap file.
What is the number of detected packets?
Note: You must answer this question correctly before answering the rest of the questions in this task.
Investigate the log file.
What is the destination address of packet 63?
Investigate the log file.
What is the ACK number of packet 64?