Jump to content


Photo
- - - - -

Snorby help


  • Please log in to reply
1 reply to this topic

#1 EonsNearby

EonsNearby

    the 0ne

  • Members
  • 1 posts
  • Gender:Male

Posted 30 January 2012 - 04:21 PM

Okay, I am a complete beginner to Snorby (and network security), so I was just wondering if anyone knows of any good tutorials that could help instruct me on how to appropriately use Snorby. One thing I need help with is sorting the thousands of events it detects. For example, one has a signature ID of 2100366, but when I query the database about it, the website it takes me to does not have any information on it. The description Snorby provides makes it sound harmless, but I want to find out a little more about it before I tell Snorby to just ignore it.

#2 Beave

Beave

    SUPR3M3 31337 Mack Daddy P1MP

  • Agents of the Revolution
  • 350 posts

Posted 07 April 2012 - 02:21 AM

Okay, I am a complete beginner to Snorby (and network security), so I was just wondering if anyone knows of any good tutorials that could help instruct me on how to appropriately use Snorby. One thing I need help with is sorting the thousands of events it detects. For example, one has a signature ID of 2100366, but when I query the database about it, the website it takes me to does not have any information on it. The description Snorby provides makes it sound harmless, but I want to find out a little more about it before I tell Snorby to just ignore it.


Your best bet is to hit the snorby forums or irc channel (irc.freenode.net). Mephux - the author of snorby usually hangs out there with various other people that can probably help




BinRev is hosted by the great people at Lunarpages!