Snort mailing list archives
Re: pcap comparison too;
From: Joel Esler <jesler () sourcefire com>
Date: Wed, 29 Aug 2012 09:27:39 -0400
On Aug 28, 2012, at 10:15 PM, David Wilson <dadamw () gmail com> wrote:
Hello, I’m looking for a tool compares .pcap files and reports differences and similarities at the hex value level for the eventual development of Snort rules. Have you ever heard of or used such a thing? Thank you very much for your help.
I've never used it, but I thought "hmm.. let's google the words pcap and diff" http://sourceforge.net/projects/pcapdiff/
------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________ Snort-sigs mailing list Snort-sigs () lists sourceforge net https://lists.sourceforge.net/lists/listinfo/snort-sigs http://www.snort.org Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- pcap comparison too; David Wilson (Aug 28)
- Re: pcap comparison too; Joel Esler (Aug 29)