OSS TanbouSign in with GitHub

An IPS for analyzing captured packets offline and validating detection rules and configuration

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
3,430
Primary language
C++
License
Not determined
Repository last updated
Apr 23, 2026
On this page

Overview

Snort 3 is an intrusion prevention and detection engine that processes packets across multiple threads and inspects traffic with rules and Lua-based configuration. Starting with a saved pcap and the installed configuration keeps evaluation offline and avoids generating attack traffic.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Inspect captured traffic with rules

Snort 3 provides multiple packet-processing threads, shared configuration, service autodetection, and pluggable components. It can read pcaps and combine rules with Lua configuration to produce alerts.

Sources: [1]

Best fit

Evaluate rules before production deployment

It fits security teams that replay representative pcaps to compare detection results before updating an IDS or IPS on a live traffic path. Offline input bounds both the test data and operational impact.

Sources: [1]

Before adoption

Plan for native dependencies and licensing

The v3.12.2.0 README lists CMake, DAQ, a C++17 compiler, LuaJIT, OpenSSL, libpcap, PCRE2, and other system libraries. GitHub reports NOASSERTION for SPDX detection, so adopters should inspect the fixed-tag LICENSE and notices for GPLv2 terms, exceptions, and component-specific conditions.

Sources: [1][3][2]

Official sources

  1. [1]snort3/snort3 README (3.12.2.0)(2026-10-04)
  2. [2]snort3/snort3 GitHub repository metadata(2026-10-04)
  3. [3]snort3/snort3 license (3.12.2.0)(2026-10-04)
  4. [4]Snort 3 3.12.2.0 release(2026-10-04)
Supplemental curator note

It is a strong candidate for teams that want to measure detections and false positives on representative captures before placing an engine on a production path. Review its DAQ, LuaJIT, and other system dependencies, along with the GPLv2 terms, exceptions, and component-specific notices.

Try it in 3 steps

  1. 1

    Clone the v3.12.2.0 source

    Clone the fixed release tag into an evaluation directory.

    git clone --branch 3.12.2.0 --depth 1 https://github.com/snort3/snort3.git && cd snort3
  2. 2

    Build into a local prefix

    After installing the README-listed system dependencies, install Snort under the current directory.

    ./configure_cmake.sh --prefix="$PWD/install" && cmake --build build -j2 && cmake --install build
  3. 3

    Validate configuration offline

    Print the built version and validate the installed configuration without capturing live traffic.

    ./install/bin/snort -V && ./install/bin/snort -c ./install/etc/snort/snort.lua -T
Check the official README

Growth

Growth trends · Last 30 days

3,430 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
0
Open PRs
27

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data
Stars
3,430
Forks
690
Watchers
126
Open issues
54
Contributors
65
Owner type
Organization
Primary language
C++
License
Not determined
Repository last updated
Apr 23, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?