This video demonstrates writing rules in Snort 3. You will need the Docker container (discussed in the Snort 3 installation video) and a running instance of Snort 3. You will learn the construction, syntax, and execution of Snort rules, look at malicious traffic samples, and look at some helpful tools for using and maintaining Snort.
There are 4 labs in this video covering basic to advanced rule usage and techniques.
Snort 3 Docker Container - https://hub.docker.com/r/ciscotalos/s...