Porkroll - A Snort Shared Object Rule Generator
Very short introduction to Porkroll, a new Snort shared object rule generator script.
Published on: Mar 4, 2016
Transcripts - Porkroll - A Snort Shared Object Rule Generator
Porkroll – A Snort SO
Who am I?
Former Cisco Talos employee
Current employee of G2, Inc
Cofounder of HardenedBSD
FreeBSD and HardenedBSD fanboy
Lover of ZFS and Dtrace
What and why?
Customer can't use plaintext rules, requires Snort Shared
Object (aka, SO) rules
Cisco Talos already has a nifty tool
– Web form only
– Screen scrape?
– Only produces C code, not deployable SO
Takes a plaintext Snort rule json object (lolwut?)
– Converts it to a fully-deployable SO
What and Why?