Skip to content

Commit

Permalink
Updates
Browse files Browse the repository at this point in the history
Removing the term “VRT” replacing with Talos.  Removing “VRT License”
Replacing with “Snort Subscriber Rule Set License”.  Removing
Sourcefire, placing with Cisco.  Removing the references to Snort
Groups, and other Misc changes such as updating URLs
  • Loading branch information
finchy committed Oct 1, 2014
1 parent b9474d0 commit 76da1fb
Show file tree
Hide file tree
Showing 46 changed files with 90 additions and 105 deletions.
3 changes: 3 additions & 0 deletions FAQ/Does-Cisco-sell-Snort.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
## Does Cisco sell Snort? ##

While Cisco does offer a commercial version of the Snort technology, we do not sell Snort. Cisco embraces the open source model and is committed to the GPL. Cisco leverages the Snort detection engine and Snort Subscriber Rule Set as the foundation for the Cisco Next Generation IPS and Next Generation Firewall, adding an easy-to-use interface, optimized hardware, powerful data analysis and reporting, policy management and administration, a full suite of product services, and 24x7 support. All enhancements made to the Snort technology for Cisco's commercial offerings are released back to the open source community.
3 changes: 0 additions & 3 deletions FAQ/Does-Sourcefire-sell-Snort.md

This file was deleted.

6 changes: 3 additions & 3 deletions FAQ/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,13 +8,13 @@

[Where can I download Snort?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/Where-can-I-download-Snort.md)

[What is the relationship between Snort and Sourcefire?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/What-is-the-relationship-between-Snort-and-Sourcefire.md)
[What is the relationship between Snort and Cisco?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/What-is-the-relationship-between-Snort-and-Cisco.md)

[Does Sourcefire sell Snort?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/Does-Sourcefire-sell-Snort.md)
[Does Cisco sell Snort?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/Does-Cisco-sell-Snort.md)

[What is a Snort Integrator?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/What-is-a-Snort-Integrator.md)

[What is the role of the Sourcefire Vulnerability Research Team (VRT)?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/What-is-the-role-of-the-VRT.md)
[What is the role of Talos?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/What-is-the-role-of-Talos.md)

[I'm not receiving alerts in Snort](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/Im-not-receiving-alerts-in-Snort.md)

Expand Down
1 change: 1 addition & 0 deletions FAQ/What-is-the-relationship-between-Snort-and-Cisco.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Sourcefire was founded in 2001 by [Martin Roesch](http://en.wikipedia.org/wiki/Martin_Roesch), the original author of Snort, in response to demand for a commercial version of the popular technology. Sourcefire was acquired by Cisco Systems on October 7, 2013. Our mission is to combine our open source roots with proprietary innovation to deliver the most effective and comprehensive real-time network defense solutions on the planet.

This file was deleted.

3 changes: 3 additions & 0 deletions FAQ/What-is-the-role-of-Talos.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
## What is the role of Talos ##

Talos is a group of leading edge network security experts working to discover, assess, and respond to the latest trends in hacking activity, intrusion attempts, and vulnerabilities. This team is also supported by the vast resources of the open source Snort community, making it the largest group dedicated to advances in the network security industry. The team authors the official Snort ruleset, the [Snort Subscriber Rule Set](https://www.snort.org/downloads/#rule-downloads) as well as all detection for [ClamAV](http://www.clamav.net) and [Razorback](http://labs.snort.org/razorback/).
3 changes: 0 additions & 3 deletions FAQ/What-is-the-role-of-the-VRT.md

This file was deleted.

4 changes: 2 additions & 2 deletions Licensing/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@

[What is the GNU GPL?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/What-is-the-GNU-GPL.md)

[What is the Sourcefire VRT Certified Rules License Agreement?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/What-is-the-Sourcefire-VRT-Certified-Rules-License-Agreement.md)
[What is the Snort Subscriber Rule Set License Agreement?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/What-is-the-Snort-Subscriber-Rule-Set-License.md)

[What is the Snort Integrator License from Sourcefire?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/What-is-the-Snort-Integrator-License-from-Sourcefire.md)
[What is the Snort Integrator License?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/What-is-the-Snort-Integrator-License.md)

[How is the Snort software licensed?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/How-is-the-Snort-Engine-Licensed.md)

Expand Down
2 changes: 1 addition & 1 deletion Licensing/What-is-the-GNU-GPL.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
The licenses for most software are designed to take away your freedom to share and change it. By contrast, the GNU General Public License is intended to guarantee your freedom to share and change free software--to make sure the software is free for all its users.

You can read the complete GPL license [here](http://www.snort.org/snort/license/gpl).
You can read the complete GPL license [here](https://www.snort.org/gpl).

This file was deleted.

1 change: 1 addition & 0 deletions Licensing/What-is-the-Snort-Integrator-License.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
The Snort Integrator License is a fee-based license that enables Snort Integrators to distribute the Snort Subscriber Rule Set with their commercial offerings. If you are interested in an integrator license, please contact us at [[email protected]]([email protected]).
2 changes: 2 additions & 0 deletions Licensing/What-is-the-Snort-Subscriber-Rule-Set-License.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
The Snort Subscriber Rule Set License Agreement enables registered end-users to freely download and use rules that have been certified by Talos while restricting commercial redistribution.
View the complete [Snort Subscribe Rule Set License Agreement](https://www.snort.org/vrt_license).

This file was deleted.

Original file line number Diff line number Diff line change
@@ -1 +1 @@
When you contribute a new rule for Snort, your rule will be included inside the Community Ruleset. Rules submitted to the Community Ruleset will be covered by the GPL. The Community Ruleset is also included in the VRT Certified Subscriber ruleset, and exclusions have been made in the VRT License to account for your submission.
When you contribute a new rule for Snort, your rule will be included inside the Community Ruleset. Rules submitted to the Community Ruleset will be covered by the GPL. The Community Ruleset is also included in the Snort Subscriber Rule Set, and exclusions have been made in the Snort Subscriber Rule Set License to account for your submission.
Original file line number Diff line number Diff line change
@@ -1 +1 @@
Sourcefire is extremely committed to the advancement of Snort and the open source community. That commitment has resulted in advances such as gigabit performance capability, the integration of the IPS technology, the current and future generations of IP defragmentation and TCP stream reassembly functionality, protocol anomaly detectors and normalization, portscan detection, the unified output subsystem, reams of documentation, and many complete code audits. In addition, Sourcefire has dedicated significant resources to improving the quality, accuracy and timeliness of Snort rules. The nature of rule development and distribution has always made the rules research, development, and distribution a parallel process with Snort development, with its own licensing needs.
We are extremely committed to the advancement of Snort and the open source community. That commitment has resulted in advances such as gigabit performance capability, the integration of the IPS technology, the current and future generations of IP defragmentation and TCP stream reassembly functionality, protocol anomaly detectors and normalization, portscan detection, the unified output subsystem, reams of documentation, and many complete code audits. In addition, Cisco has dedicated significant resources to improving the quality, accuracy and timeliness of Snort rules. The nature of rule development and distribution has always made the rules research, development, and distribution a parallel process with Snort development, with its own licensing needs.
2 changes: 1 addition & 1 deletion Lists/Where-do-I-submit-questions-about-Snort.md
Original file line number Diff line number Diff line change
@@ -1 +1 @@
The open source community is very important to Sourcefire and we welcome your feedback. The Snort Team, VRT, and others at Sourcefire monitor the [Snort mailing lists](http://www.snort.org/community/mailing-lists) and IRC channel. (#Snort on Freenode) Questions and comments about Snort should be submitted to one of these channels so the entire community can benefit. Feedback on Snort.org can be sent directly to Sourcefire at [snort-site@sourcefire.com](snort-site@sourcefire.com).
The open source community is very important to us and we welcome your feedback. The Snort Team, Talos, and others monitor the [Snort mailing lists](https://www.snort.org/community) and IRC channel. (#Snort on Freenode) Questions and comments about Snort should be submitted to one of these channels so the entire community can benefit. Feedback on Snort.org can be sent directly to us at [snort-site@cisco.com](snort-site@cisco.com).
30 changes: 13 additions & 17 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,13 +17,13 @@ To checkout all the files:

[Where can I download Snort?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/Where-can-I-download-Snort.md)

[What is the relationship between Snort and Sourcefire?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/What-is-the-relationship-between-Snort-and-Sourcefire.md)
[What is the relationship between Snort and Cisco?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/What-is-the-relationship-between-Snort-and-Cisco.md)

[Does Sourcefire sell Snort?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/Does-Sourcefire-sell-Snort.md)
[Does Cisco sell Snort?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/Does-Cisco-sell-Snort.md)

[What is a Snort Integrator?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/What-is-a-Snort-Integrator.md)

[What is the role of the Sourcefire Vulnerability Research Team (VRT)?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/What-is-the-role-of-the-VRT.md)
[What is the role of Talos?](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/What-is-the-role-of-Talos.md)

[I'm not receiving alerts in Snort](https://github.com/vrtadmin/snort-faq/blob/master/FAQ/Im-not-receiving-alerts-in-Snort.md)

Expand All @@ -49,10 +49,6 @@ To checkout all the files:

[How can I provide feedback or suggestions for the site?](https://github.com/vrtadmin/snort-faq/blob/master/Snort.org/How-can-I-provide-feedback-or-suggestions-for-the-site.md)

[How can I find a user group in my area?](https://github.com/vrtadmin/snort-faq/blob/master/Snort.org/How-can-I-find-a-user-group-in-my-area.md)

[What if there isn't a local group?](https://github.com/vrtadmin/snort-faq/blob/master/Snort.org/What-if-there-isn't-a-local-group.md)

### Rules ###

[What is a Snort rule?](https://github.com/vrtadmin/snort-faq/blob/master/Rules/What-is-a-Snort-rule.md)
Expand All @@ -67,7 +63,7 @@ To checkout all the files:

[What are Community Rules?](https://github.com/vrtadmin/snort-faq/blob/master/Rules/What-are-community-rules.md)

[What are Sourcefire VRT Certified Rules?](https://github.com/vrtadmin/snort-faq/blob/master/Rules/What-are-Sourcefire-VRT-Certified-Rules.md)
[What are Snort Subscriber Rule Set?](https://github.com/vrtadmin/snort-faq/blob/master/Rules/What-is-the-Snort-Subscriber-Rule-Set.md)

[What is a user-defined rule?](https://github.com/vrtadmin/snort-faq/blob/master/Rules/What-is-a-user-defined-rule.md)

Expand All @@ -77,27 +73,27 @@ To checkout all the files:

[Resolving Flowbit Dependancies](https://github.com/vrtadmin/snort-faq/blob/master/Rules/Resolving-flowbit-dependancies.md)

### Sourcefire VRT Subscription ###
### Snort Subscriber Rule Set Subscription ###

[What does having a Sourcefire VRT subscription entitle me to?](https://github.com/vrtadmin/snort-faq/blob/master/VRT%20Subscription/What-does-the-Sourcefire-VRT-Certified-Rules-Subscription-entitle-me-to.md)
[What does having a Snort Subscriber Rule Set subscription entitle me to?](https://github.com/vrtadmin/snort-faq/blob/master/Snort%20Subscriber%20Rule%Set/What-does-the-Snort-Subscriber-Rule-Set-entitle-me-to.md)

[Do I have to subscribe to receive Sourcefire VRT rules?](https://github.com/vrtadmin/snort-faq/blob/master/VRT%20Subscription/Do-I-have-to-subscribe-to-receive-Sourcefire-VRT-rules.md)
[Do I have to subscribe to receive the Snort Subscriber Rule Set?](https://github.com/vrtadmin/snort-faq/blob/master/Snort%20Subscriber%20Rule%Set/Do-I-have-to-subscribe-to-receive-rules.md)

[How much does a subscription cost?](https://github.com/vrtadmin/snort-faq/blob/master/VRT%20Subscription/How-much-does-a-subscription-cost.md)
[How much does a subscription cost?](https://github.com/vrtadmin/snort-faq/blob/master/Snort%20Subscriber%20Rule%Set/How-much-does-a-subscription-cost.md)

[If I purchase a subscription, can I deploy the rules on more than one sensor?](https://github.com/vrtadmin/snort-faq/blob/master/VRT%20Subscription/If-I-purchase-a-subscription,-can-I-deploy-the-rules-on-other-sensors.md)
[If I purchase a subscription, can I deploy the rules on more than one sensor?](https://github.com/vrtadmin/snort-faq/blob/master/Snort%20Subscriber%20Rule%Set/If-I-purchase-a-subscription,-can-I-deploy-the-rules-on-other-sensors.md)

[Can I use tools such as PulledPork to manage the subscription?](https://github.com/vrtadmin/snort-faq/blob/master/VRT%20Subscription/Can-I-use-tools-such-as-PulledPork-to-manage-the-subscription.md)
[Can I use tools such as PulledPork to manage the subscription?](https://github.com/vrtadmin/snort-faq/blob/master/Snort%20Subscriber%20Rule%Set/Can-I-use-tools-such-as-PulledPork-to-manage-the-subscription.md)

[Where do I go to subscribe to the Sourcefire VRT Certified Ruleset?](https://github.com/vrtadmin/snort-faq/blob/master/VRT%20Subscription/Where-can-I-go-to-subscribe-to-the-ruleset.md)
[Where do I go to subscribe to the Snort Subscriber Rule Set?](https://github.com/vrtadmin/snort-faq/blob/master/Snort%20Subscriber%20Rule%Set/Where-can-I-go-to-subscribe-to-the-ruleset.md)

### Licensing ###

[What is the GNU GPL?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/What-is-the-GNU-GPL.md)

[What is the Sourcefire VRT Certified Rules License Agreement?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/What-is-the-Sourcefire-VRT-Certified-Rules-License-Agreement.md)
[What is the Snort Subscriber Rule Set License Agreement?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/What-is-the-Snort-Subscriber-Rule-Set-License.md)/

[What is the Snort Integrator License from Sourcefire?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/What-is-the-Snort-Integrator-License-from-Sourcefire.md)
[What is the Snort Integrator License?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/What-is-the-Snort-Integrator-License.md)

[How is the Snort software licensed?](https://github.com/vrtadmin/snort-faq/blob/master/Licensing/How-is-the-Snort-Engine-Licensed.md)

Expand Down
6 changes: 3 additions & 3 deletions Rules/How-are-rules-distributed.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
There are two sets of rules distributed on the snort.org web site. The "Community Ruleset" is freely available to all users. The "Sourcefire VRT Certified Rulesets" will be made available to users in the following ways:
There are two sets of rules distributed on the snort.org web site. The "Community Ruleset" is freely available to all users. The "Snort Subscriber Rule Set" will be made available to users in the following ways:

* Subscribers will receive rulesets in real-time as they are released to Sourcefire customers - 30 days ahead of registered users
* Subscribers will receive rulesets in real-time as they are released to Cisco customers - 30 days ahead of registered users
* Registered users will receive rulesets 30 days after Subscribers.
* Unregistered users will receive access to the community ruleset.

The rules are available for download [here](http://www.snort.org/snort-rules).
The rules are available for download [here](https://www.snort.org/downloads/#rule-downloads).
2 changes: 1 addition & 1 deletion Rules/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@

[What are Community Rules?](https://github.com/vrtadmin/snort-faq/blob/master/Rules/What-are-community-rules.md)

[What are Sourcefire VRT Certified Rules?](https://github.com/vrtadmin/snort-faq/blob/master/Rules/What-are-Sourcefire-VRT-Certified-Rules.md)
[What is the Snort Subscriber Rule Set?](https://github.com/vrtadmin/snort-faq/blob/master/Rules/What-is-the-Snort-Subscriber-Rule-Set.md)

[What is a user-defined rule?](https://github.com/vrtadmin/snort-faq/blob/master/Rules/What-is-a-user-defined-rule.md)

Expand Down
2 changes: 1 addition & 1 deletion Rules/Resolving-flowbit-dependancies.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ In other words, flowbits allow you to set and track the state of a flow in betwe

Let me explain the two "warning" messages above.

First, the group name of the flowbit that has the "problem" is "`http.rtf`". In the VRT, we have a naming convention that we use for flowbits, and this name above tells me that this is an "RTF" document being downloaded over HTTP. In other words, the way the rules are going to be written means that someone on your network has requested an "rtf" document.
First, the group name of the flowbit that has the "problem" is "`http.rtf`". In Talos, we have a naming convention that we use for flowbits, and this name above tells me that this is an "RTF" document being downloaded over HTTP. In other words, the way the rules are going to be written means that someone on your network has requested an "rtf" document.

`Warning: flowbits key 'http.rtf' is set but not ever checked.`

Expand Down
1 change: 0 additions & 1 deletion Rules/What-are-Sourcefire-VRT-Certified-Rules.md

This file was deleted.

Loading

0 comments on commit 76da1fb

Please sign in to comment.