OpenBSD Handbook

Current snapshot · amd64 · Generated 2026-09-09

snort-2.9.20p7

highly flexible sniffer/NIDS

Back to search · Project homepage

Description

Snort is an open source network intrusion detection and prevention system. It is capable of performing real-time traffic analysis, alerting, blocking and packet logging on IP networks. It utilizes a combination of protocol analysis and pattern matching in order to detect a anomalies, misuse and attacks. Snort uses a flexible rules language to describe activity that can be considered malicious or anomalous as well as an analysis engine that incorporates a modular plugin architecture. Snort is capable of detecting and responding in real-time, sending alerts, performing session sniping, logging packets, or dropping sessions/packets when deployed in-line. Snort has three primary functional modes. It can be used as a packet sniffer like tcpdump(8), a packet logger (useful for network traffic debugging, etc), or as a full blown network intrusion detection and prevention system.

Package information

Ports path
net/snort
Package architecture
amd64
Maintainer
The OpenBSD ports mailing-list <ports@openbsd.org>
Categories
net, security
Available flavors
no_luajit

These are ports metadata. Binary availability depends on the release, architecture and mirror. Build and test dependencies are not an installation checklist.

Direct dependencies

Library

OpenBSD README

This README contains unresolved ports variables. It is source documentation; commands containing these variables require adjustment.

Installing and updating packages · Package details as JSON