ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] How do I use wireshark to investigate Snort IDS alert "A Netwo

From: Turritopsis Dohrnii Teo En Ming <turritopsis.dohrnii@xxxxxxxxxxxxxxx>
Date: Mon, 22 Oct 2018 15:02:12 +0000
Good evening from Singapore,

I have the following alert "A Network Trojan was Detected" in my Snort Intrusion Detection System (IDS) which is in my pfSense Network Security Appliance.

Thread: [Snort-users] Snort IDS in pfSense Network Security Appliance: "A Network Trojan was Detected"

URL: https://lists.snort.org/pipermail/snort-users/2018-October/071833.html

Is there any way I can use wireshark to pin-point the operating system process in memory or filesystem object which is triggering the above-mentioned Snort IDS/IPS alert? I am hoping to know which executable file is triggering this IDS/IPS alert.

Please advise.

Thank you very much.     
 
===BEGIN SIGNATURE===
 
Turritopsis Dohrnii Teo En Ming's Academic Qualifications as at 30 Oct 2017 

[1] https://tdtemcerts.wordpress.com/ 

[2] http://tdtemcerts.blogspot.sg/ 

[3] https://www.scribd.com/user/270125049/Teo-En-Ming 

===END SIGNATURE===