Thursday, January 13, 2011

Polman, another rule manager for Snort

Most people know about rule management tools for Snort, Oinkmaster and even PulledPork, however, one of the members of the Snort community, Edward Fjellskål, decided that neither one of those tools was for him, so he wrote a rule manager, with kind of a different twist to it.

It's called Polman, it uses a "database" type format, and allows for mass enable, disable, search, and display of rules.  I think the concept has a lot of merit.

Check out the example here, and check out the blog post about the tool here.  A link for the download for the tool is on the blog post.