On this page
Overview
Snort 3 is an intrusion prevention and detection engine that processes packets across multiple threads and inspects traffic with rules and Lua-based configuration. Starting with a saved pcap and the installed configuration keeps evaluation offline and avoids generating attack traffic.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Inspect captured traffic with rules
Snort 3 provides multiple packet-processing threads, shared configuration, service autodetection, and pluggable components. It can read pcaps and combine rules with Lua configuration to produce alerts.
Sources: [1]
Best fit
Evaluate rules before production deployment
It fits security teams that replay representative pcaps to compare detection results before updating an IDS or IPS on a live traffic path. Offline input bounds both the test data and operational impact.
Sources: [1]
Before adoption
Plan for native dependencies and licensing
The v3.12.2.0 README lists CMake, DAQ, a C++17 compiler, LuaJIT, OpenSSL, libpcap, PCRE2, and other system libraries. GitHub reports NOASSERTION for SPDX detection, so adopters should inspect the fixed-tag LICENSE and notices for GPLv2 terms, exceptions, and component-specific conditions.
Official sources
- [1]snort3/snort3 README (3.12.2.0)(2026-10-04)
- [2]snort3/snort3 GitHub repository metadata(2026-10-04)
- [3]snort3/snort3 license (3.12.2.0)(2026-10-04)
- [4]Snort 3 3.12.2.0 release(2026-10-04)
Supplemental curator note
It is a strong candidate for teams that want to measure detections and false positives on representative captures before placing an engine on a production path. Review its DAQ, LuaJIT, and other system dependencies, along with the GPLv2 terms, exceptions, and component-specific notices.
Try it in 3 steps
- 1
Clone the v3.12.2.0 source
Clone the fixed release tag into an evaluation directory.
git clone --branch 3.12.2.0 --depth 1 https://github.com/snort3/snort3.git && cd snort3 - 2
Build into a local prefix
After installing the README-listed system dependencies, install Snort under the current directory.
./configure_cmake.sh --prefix="$PWD/install" && cmake --build build -j2 && cmake --install build - 3
Validate configuration offline
Print the built version and validate the installed configuration without capturing live traffic.
./install/bin/snort -V && ./install/bin/snort -c ./install/etc/snort/snort.lua -T
Growth
Growth trends · Last 30 days
3,430 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 0
- Open PRs
- 27
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
- Stars
- 3,430
- Forks
- 690
- Watchers
- 126
- Open issues
- 54
- Contributors
- 65
- Owner type
- Organization
- Primary language
- C++
- License
- Not determined
- Repository last updated
- Apr 23, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Windows Terminal105,073 Stars
1 shared tag(s) · Same language
Use tabs, panes, and multiple command-line profiles in one modern Windows terminal
C++ - OpenCV91,053 Stars
1 shared tag(s) · Same language
a computer-vision foundation with major toolchain and API changes in 5.0
C++ - Bitcoin Core90,305 Stars
1 shared tag(s) · Same language
Fully validate Bitcoin peer-to-peer blocks and transactions yourself while optionally running wallet and RPC services on the same node
C++ - GPT4All77,388 Stars
1 shared tag(s) · Same language
choose a model and start local chat and document search on a personal computer
C++ - JSON for Modern C++50,720 Stars
1 shared tag(s) · Same language
build, parse, transform, and serialize JSON as C++ values
C++ - GoogleTest39,618 Stars
1 shared tag(s) · Same language
write C++ unit tests, assertions, parameterized tests, death tests, and mocks with Google's testing framework
C++
Report incorrect information
Tell us if any listing information is incorrect or outdated.