June 2, 2024, 12:19 p.m. | /u/saadjumani

cybersecurity www.reddit.com

Hi, im wondering if if someone has used snort as an IDS specifically for OT envoirnments. Ive seen there are OT related rules in snort (600 in total if im not wrong) for different OT/ICS protocols like modbus and IEC 104, but ive also heard someone say that Snort isn't recomended for OT envoirnments. Im taking it with a pinch of salt because said person is also affiliated with a company that sells its own OT monitoring solutions …

cybersecurity ics ids iec iot modbus monitoring protocols rules snort tips wrong yes

Security architect (SOC)

@ Alter Solutions | Paris, France

Principal Member of Technical Staff

@ Oracle | Romania

Head of Digital Security & Compliance

@ Vattenfall | Kolding, Denmark

IT Security Engineer

@ Vontobel | Zürich / Splügenstrasse 5

Information System Security Officer

@ Booz Allen Hamilton | USA, GA, Warner Robins (300 Park Pl Dr)

Senior CyberArk Security Engineer

@ Manulife | CAN, Ontario, Toronto, 200 Bloor Street East