Alternatives to Snort

Open-source intrusion detection and prevention system. The listings below can replace it for an important use case. Each note says what changes if you switch.

The original

Replacements

Listings that take over the same core job as Snort.

  • Suricata

    Inspect network traffic with an intrusion-detection engine.

    Suricata is a GPL-2.0 intrusion detection engine for Linux that also supports inline prevention, while Snort additionally runs on Windows and offers a paid subscriber rule set.

  • Zeek

    Network analysis framework that turns traffic into high-level activity logs.

    Zeek turns traffic into high-level activity logs with its own scripting language instead of signature alerts, running on Linux and macOS under a BSD licence.

  • Security Onion

    A free Linux distribution for network security monitoring, packet capture, detection and threat hunting.

    Security Onion is a full Linux monitoring distribution installed from one ISO, bundling detection, packet capture and threat hunting, but it needs dedicated hardware and setup time.

Similar software

Related functionality, not a direct replacement.