You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Install Snort on your virtual machine and verify the installation by running 'snort -V' in the terminal to display the current version.
2.
Configure Snort to monitor all incoming and outgoing traffic on your VM’s primary network interface and log alerts to a file named snort.log.
3.
Simulate a network scan from another device (or VM) using the nmap tool, and check if Snort generates an alert in the log file for this suspicious activity.<br><br><em><strong>Hint:</strong> Use 'nmap -sS [your VM IP]' from another machine on the same network.</em>
4.
Edit your Snort configuration to only alert on HTTP traffic (port 80) and test by browsing any website from your VM, then verify that only HTTP-related alerts appear in snort.log.<br><br><em><strong>Constraint:</strong> Do not alert for other ports like 22 or 443.</em> #139