How to find rule which have sid,des alert?
hvtuan297 last edited by
Currently, I have alerts with SID,desc,…
So how can I know it from what category rule ?
micropone last edited by
bmeeks last edited by
There once was a web site out there where you could do that (match a GID:SID with category). I'm not sure it exists or is maintained anymore. I no longer have the URL.
You can open a CLI prompt on the firewall and use grep to find a GID:SID within the rules. To search all the available categories, grep all the *.rules files in this directory for Snort:
If you have Suricata instead, then search the files in this directory: