Developer docs
API playgroundTry for free, no card

Search company profiles

Snort

Full company profile

uuid000f8kq

Namestring
Snort
Legal namestring
Cisco Systems, Inc.
Websiteurl
snort.org
Company typeenum
Private
Founded yearint
1998
Descriptiontext

Snort is an open-source network intrusion detection and prevention system (IPS) created in 1998 by Martin Roesch and now owned and maintained by Cisco Systems, Inc. following Cisco's October 2013 acquisition of Sourcefire. The software performs real-time traffic analysis, packet logging, and content matching against a rule-based detection engine, and can be deployed as a packet sniffer, packet logger, or full inline IPS. The current generation — Snort 3 — uses Lua-based configuration, multi-threaded processing, and a plug-in architecture with 200+ extensions; legacy Snort 2 (final version 2.9.20) remains in long-term support. Threat detection content is delivered through a tiered ruleset model: a free Community Ruleset (GPLv2, daily updates), a free Registered Rule Set (30-day delay, available with snort.org registration), and a paid Snort Subscriber Ruleset developed and QAed by the Cisco Talos intelligence team and delivered in real time. Pricing for the subscriber ruleset starts at $29.99/year for personal accounts, with business pricing available on request; commercial use of the proprietary rules in products or services additionally requires a separate Snort Integrator License.

Snort serves a heterogeneous customer base spanning individual security enthusiasts and home-lab users, small and mid-market organizations, large enterprises (often indirectly via Cisco Secure Firewall / Firepower Threat Defense appliances that embed Snort), and commercial security vendors and MSSPs that bundle the engine or rules under the Integrator License. The product portfolio is complemented by OpenAppID for application-layer detection, the Talos LightSPD unified rules package, a Sample IP Block List, and SnortML — a TensorFlow-based LSTM machine learning engine introduced in 2024 for zero-day HTTP exploit detection. The go-to-market is hybrid: community-led growth through snort.org, GitHub, Docker Hub, mailing lists, Discord, blogs, and a $10,000 annual cybersecurity scholarship, paired with sales-led enterprise motion via the Cisco Partner channel using product code L-FP-VRT-1Y. Snort does not publicly report standalone revenue, and the business is not structured as a discrete revenue-reporting entity within Cisco; the project's value to Cisco is best understood as a threat-intelligence and ecosystem anchor for the broader Cisco Security portfolio rather than a standalone P&L.

Short descriptiontext

Snort is an open-source network intrusion prevention system owned and maintained by Cisco, offering rule-based and ML-based (SnortML) real-time traffic analysis to enterprises, security vendors, MSSPs, and individual users via free engine downloads and a paid Talos-branded subscriber ruleset.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
51–100
akta.pro rankint
HeadquartersColumbia, United States
HQ citystring
Columbia
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Keyword5 values
network intrusion prevention, intrusion detection system, open source security, threat detection rules, network security software
Industry2 codes
1Next-Generation Firewalls (NGFW)
CodeHDAFAFAAPrimaryYes
2Next-Gen Firewalls (NGFW) & UTM
CodeHDADABAAPrimaryNo
Product category
Network Intrusion Prevention System (IPS)
Social media profiles2 records
GTM motion2 records

Each record includes

Type, Description, Source

Revenue model4 records
1Snort Subscriber Rule Set Subscription
TypeSubscription Recurring
Description

Paid subscription providing real-time access to Talos-developed detection rules, 30 days ahead of registered users. Rules developed by Cisco Talos intelligence team. Subscribers receive fastest access to updates, same ruleset as Cisco customers, ability to submit false positives directly to Talos support.

snort.org
2Commercial Rule License
TypeLicensing Royalties
Description

Separate commercial license agreement required for using rules in commercial products or for fee-based services. Sold through Cisco Partners with product code L-FP-VRT-1Y.

snort.org
3Snort Integrator License
TypeLicensing Royalties
Description

Fee-based license enabling Snort Integrators to distribute Snort Subscriber Rule Set with commercial offerings. Contact [email protected] for pricing.

snort.org
4Community Ruleset
TypeFreemium
Description

Freely available rules developed by the open source community and QAed by Cisco Talos. Governed by GPLv2. Included in subscriber downloads.

snort.org
Marketing channels9 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels5 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Pricing details5 tiers
1Personal Subscription - Snort Subscriber Rule Set
ModelSubscriptionBilling cadenceAnnual
Notes

Personal account subscription for individual users. Provides real-time access to Talos rules, 30 days ahead of registered users. Starting price mentioned as $29.99/year.

blog.snort.org
2Business Subscription - Snort Subscriber Rule Set
ModelSubscriptionBilling cadenceAnnual
Notes

Business pricing available. Requires contact with Cisco Partner or Snort team for quote. Product code L-FP-VRT-1Y for partner purchases.

blog.snort.org
3Registered User (Free Tier)
ModelFreemiumBilling cadenceAnnual
Notes

Free registration provides access to Registered Rule Set, 30 days behind subscriber release. Includes Community Ruleset.

snort.org
4Community Ruleset (Free)
ModelFreemiumBilling cadencePay-as-you-go
Notes

Completely free, no registration required. GPLv2 licensed. Updated daily. Subset of subscriber ruleset.

snort.org
5Snort Integrator License (Commercial)
ModelOne time/ perpetual licenseBilling cadenceMulti-year contract
Notes

Fee-based commercial license for distributing subscriber rulesets with commercial products. Contact [email protected] for pricing.

snort.org
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 of 5 records shown
1Snort 3
Description

The next generation of Snort Intrusion Prevention System featuring Lua-based configuration, multi-threaded processing, improved scalability, and 200+ plugins.

snort.org
+4 more records
Core offering1 text field

Snort is an open-source network intrusion prevention system (IPS) that performs real-time traffic analysis and packet logging on IP networks using a rule-based detection engine. The software is freely distributed under GPL v2 and is available alongside tiered rulesets (free Community Ruleset, free Registered Rule Set, and paid Talos Subscriber Rule Set) for detecting exploits, zero-day threats, and anomalous traffic. Snort is deployed by enterprises, individual users, MSSPs, and OEMs, and is also sold under a commercial Snort Integrator License for bundling in third-party products.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • 5 million+ software downloads
+3 more records
Product overview1 text field

Snort is an open-source Network Intrusion Prevention System (IPS) developed by Cisco and maintained by the Snort community. The product portfolio centers on the Snort Core Engine (available as Snort 3, the current next-generation version with Lua configuration and 200+ plugins, and Snort 2, a legacy version still supported at 2.9.20). Rule-based threat detection is delivered through tiered rulesets: the free Community Ruleset (GPLv2, updated daily), the free Registered Rule Set (30-day delay from subscribers), and the commercial Snort Subscriber Rule Set (real-time access, developed by Cisco Talos). Additional products include OpenAppID for application-layer detection, the Talos LightSPD rules package for unified Snort 3 rule management, the Sample IP Block List, and SnortML - a machine learning-based exploit detection engine launched in 2024 that addresses zero-day threats using TensorFlow neural networks. The ecosystem includes community tools like PulledPork for automated rule management and Snort2Lua for configuration migration. Snort can be purchased for commercial use via the Snort Integrator License, and educational resources include webcasts, documentation, and an annual scholarship program.

Product and service7 records
1Snort 3
CategoryNetwork Intrusion Prevention System
Description

The next-generation Snort Intrusion Prevention System featuring enhanced performance, faster processing, improved network scalability, and over 200 plugins. Uses Lua-based configuration and replaces Snort 2.x configuration syntax.

2Snort 2
CategoryNetwork Intrusion Detection System (Legacy)
Description

Legacy version of Snort Intrusion Detection System. Latest supported version is 2.9.20. Users are encouraged to upgrade to Snort 3 for improved features and ongoing support.

3Snort Subscriber Rule Set
4Community Ruleset
CategoryOpen Source Ruleset
Description

Freely available ruleset developed by the Snort open source community and QAed by Cisco Talos. Governed by GNU GPL v2, updated daily, and accessible without registration.

5Registered Rule Set
CategoryFree Registered Ruleset
Description

Free ruleset available to registered Snort.org users. Contains the community ruleset plus additional rules, but with a 30-day delay from the subscriber release.

6Talos LightSPD Rules Package
CategoryUnified Rules Package
Description

A singular rules package that contains configurations for every version of Snort 3 and Shared Object rules for all supported versions and architectures, in addition to the latest versions of all rules. Recommended for ensuring compatibility across Snort 3 versions.

7Daemonlogger
CategoryPacket Capture and Logging Tool
Description

Libpcap-based packet logger and soft tap developed by Martin Roesch. Can sniff packets and spool to disk with 2GB file rollover, or rewrite packets to a second interface acting as a soft tap. Licensed under GPL v2 with Cisco clarifications.

Scale indicator6 records

Each record includes

Type, Value, Description, Source

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Open-source network IDS/IPS/NSM engine developed by the OISF foundation; directly competes with Snort on rule-based and protocol-aware network detection, and is positioned by many as the higher-performance alternative in the same deployment scenarios.

TypeDirect peer
Description

Open-source network security monitor focused on rich semantic traffic analysis and behavioral logs; commonly deployed alongside or instead of Snort for network detection, sharing the same target users (SOC analysts, IDS operators).

TypeDirect peer
Description

Commercial vendor built on Zeek that delivers enterprise-grade network detection and response appliances and SaaS; competes for the same enterprise budget as Snort-based deployments, particularly where richer analytics are valued over pure signature matching.

TypeDirect peer
Description

Linux distribution for IDS, NSM, and log management that bundles Snort, Suricata, Zeek, and Elastic Stack; a closely adjacent open-source platform that competes for the same SOC/network-security-monitoring buyer, where Snort is one of several engines it ships.

TypeBroad incumbent
Description

Cisco's commercial NGFW product line that runs Snort under the hood for IPS/IDS; competes with Snort-as-standalone in enterprises that prefer an integrated appliance, and is the primary vehicle through which Cisco monetizes Snort technology.

TypeBroad incumbent
Description

Market-leading NGFW vendor with App-ID and Threat Prevention; competes with Snort-based IPS deployments in enterprise network security, offering an integrated alternative to standalone open-source IPS.

TypeBroad incumbent
Description

Broad incumbent NGFW/UTM vendor with integrated IPS, sandboxing, and SD-WAN; competes with Snort in mid-market and enterprise network security, often replacing or being evaluated against Snort in greenfield deployments.

TypeBroad incumbent
Description

Enterprise NGFW and threat prevention platform; competes with Snort-based IPS in enterprise perimeter and data-center deployments, often as part of broader Check Point Infinity architecture.

TypeEmerging player
Description

AI-driven network detection and response vendor using unsupervised machine learning for anomaly-based threat detection; competes with Snort for the network detection budget, especially in enterprises prioritizing behavioral over signature-based detection.

TypeEmerging player
Description

Network detection and response platform using AI to surface attacker behaviors across cloud, SaaS, and on-prem networks; overlaps with Snort's use case in SOC workflows, particularly where ML-driven triage is preferred over ruleset management.

Market position
Strengths4 records

Each record includes

Headline, Details, Source

Weaknesses4 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers1 record

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration10 records

Each record includes

Title, Type, Description, Source

AI capability3 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature9 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles3 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Snort

Network Intrusion Prevention System (IPS)snort.org

Snort is an open-source network intrusion prevention system owned and maintained by Cisco, offering rule-based and ML-based (SnortML) real-time traffic analysis to enterprises, security vendors, MSSPs, and individual users via free engine downloads and a paid Talos-branded subscriber ruleset.

What Snort does

Snort is an open-source network intrusion detection and prevention system (IPS) created in 1998 by Martin Roesch and now owned and maintained by Cisco Systems, Inc. following Cisco's October 2013 acquisition of Sourcefire. The software performs real-time traffic analysis, packet logging, and content matching against a rule-based detection engine, and can be deployed as a packet sniffer, packet logger, or full inline IPS. The current generation — Snort 3 — uses Lua-based configuration, multi-threaded processing, and a plug-in architecture with 200+ extensions; legacy Snort 2 (final version 2.9.20) remains in long-term support. Threat detection content is delivered through a tiered ruleset model: a free Community Ruleset (GPLv2, daily updates), a free Registered Rule Set (30-day delay, available with snort.org registration), and a paid Snort Subscriber Ruleset developed and QAed by the Cisco Talos intelligence team and delivered in real time. Pricing for the subscriber ruleset starts at $29.99/year for personal accounts, with business pricing available on request; commercial use of the proprietary rules in products or services additionally requires a separate Snort Integrator License.

Snort serves a heterogeneous customer base spanning individual security enthusiasts and home-lab users, small and mid-market organizations, large enterprises (often indirectly via Cisco Secure Firewall / Firepower Threat Defense appliances that embed Snort), and commercial security vendors and MSSPs that bundle the engine or rules under the Integrator License. The product portfolio is complemented by OpenAppID for application-layer detection, the Talos LightSPD unified rules package, a Sample IP Block List, and SnortML — a TensorFlow-based LSTM machine learning engine introduced in 2024 for zero-day HTTP exploit detection. The go-to-market is hybrid: community-led growth through snort.org, GitHub, Docker Hub, mailing lists, Discord, blogs, and a $10,000 annual cybersecurity scholarship, paired with sales-led enterprise motion via the Cisco Partner channel using product code L-FP-VRT-1Y. Snort does not publicly report standalone revenue, and the business is not structured as a discrete revenue-reporting entity within Cisco; the project's value to Cisco is best understood as a threat-intelligence and ecosystem anchor for the broader Cisco Security portfolio rather than a standalone P&L.

Snort firmographics

Firmographics
Name
Snort
Legal name
Cisco Systems, Inc.
Website
https://snort.org
Company type
Private
Founded year
1998
Operating status
Operating
Headcount range
51–100 employees
Short description
Snort is an open-source network intrusion prevention system owned and maintained by Cisco, offering rule-based and ML-based (SnortML) real-time traffic analysis to enterprises, security vendors, MSSPs, and individual users via free engine downloads and a paid Talos-branded subscriber ruleset.
Ownership category
akta.pro rank

Snort industry classification

Industry
Product category
Network Intrusion Prevention System (IPS)
akta.pro primary industry
Next-Generation Firewalls (NGFW) (HDAFAFAA)
akta.pro secondary industry
Next-Gen Firewalls (NGFW) & UTM (HDADABAA)

Keywords

  • Network intrusion prevention
  • Intrusion detection system
  • Open source security
  • Threat detection rules
  • Network security software

Where Snort is headquartered

Location

Headquarters

HQ city
Columbia
HQ country
United States
HQ region
North America

Markets served

Snort business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations

Revenue model

  1. Snort Subscriber Rule Set Subscription: Paid subscription providing real-time access to Talos-developed detection rules, 30 days ahead of registered users. Rules developed by Cisco Talos intelligence team. Subscribers receive fastest access to updates, same ruleset as Cisco customers, ability to submit false positives directly to Talos support.
  2. Commercial Rule License: Separate commercial license agreement required for using rules in commercial products or for fee-based services. Sold through Cisco Partners with product code L-FP-VRT-1Y.
  3. Snort Integrator License: Fee-based license enabling Snort Integrators to distribute Snort Subscriber Rule Set with commercial offerings. Contact [email protected] for pricing.
  4. Community Ruleset: Freely available rules developed by the open source community and QAed by Cisco Talos. Governed by GPLv2. Included in subscriber downloads.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualPersonal Subscription - Snort Subscriber Rule Set
SubscriptionAnnualBusiness Subscription - Snort Subscriber Rule Set
FreemiumAnnualRegistered User (Free Tier)
FreemiumPay-as-you-goCommunity Ruleset (Free)
One time/ perpetual licenseMulti-year contractSnort Integrator License (Commercial)

Go-to-market motion2 records

Distribution channels5 records

Marketing channels9 records

Snort product offering

Product offering

Core offering

Snort is an open-source network intrusion prevention system (IPS) that performs real-time traffic analysis and packet logging on IP networks using a rule-based detection engine. The software is freely distributed under GPL v2 and is available alongside tiered rulesets (free Community Ruleset, free Registered Rule Set, and paid Talos Subscriber Rule Set) for detecting exploits, zero-day threats, and anomalous traffic. Snort is deployed by enterprises, individual users, MSSPs, and OEMs, and is also sold under a commercial Snort Integrator License for bundling in third-party products.

Product overview

Snort is an open-source Network Intrusion Prevention System (IPS) developed by Cisco and maintained by the Snort community. The product portfolio centers on the Snort Core Engine (available as Snort 3, the current next-generation version with Lua configuration and 200+ plugins, and Snort 2, a legacy version still supported at 2.9.20). Rule-based threat detection is delivered through tiered rulesets: the free Community Ruleset (GPLv2, updated daily), the free Registered Rule Set (30-day delay from subscribers), and the commercial Snort Subscriber Rule Set (real-time access, developed by Cisco Talos). Additional products include OpenAppID for application-layer detection, the Talos LightSPD rules package for unified Snort 3 rule management, the Sample IP Block List, and SnortML - a machine learning-based exploit detection engine launched in 2024 that addresses zero-day threats using TensorFlow neural networks. The ecosystem includes community tools like PulledPork for automated rule management and Snort2Lua for configuration migration. Snort can be purchased for commercial use via the Snort Integrator License, and educational resources include webcasts, documentation, and an annual scholarship program.

Differentiator

Problem solved

Functional benefit

Brands

  • Snort 3: The next generation of Snort Intrusion Prevention System featuring Lua-based configuration, multi-threaded processing, improved scalability, and 200+ plugins.
  • Snort 2
  • OpenAppID
  • Talos Ruleset
  • Community Ruleset

Products and services

  • Snort 3 The next-generation Snort Intrusion Prevention System featuring enhanced performance, faster processing, improved network scalability, and over 200 plugins. Uses Lua-based configuration and replaces Snort 2.x configuration syntax.
  • Snort 2 Legacy version of Snort Intrusion Detection System. Latest supported version is 2.9.20. Users are encouraged to upgrade to Snort 3 for improved features and ongoing support.
  • Snort Subscriber Rule Set
  • Community Ruleset Freely available ruleset developed by the Snort open source community and QAed by Cisco Talos. Governed by GNU GPL v2, updated daily, and accessible without registration.
  • Registered Rule Set Free ruleset available to registered Snort.org users. Contains the community ruleset plus additional rules, but with a 30-day delay from the subscriber release.
  • Talos LightSPD Rules Package A singular rules package that contains configurations for every version of Snort 3 and Shared Object rules for all supported versions and architectures, in addition to the latest versions of all rules. Recommended for ensuring compatibility across Snort 3 versions.
  • Daemonlogger Libpcap-based packet logger and soft tap developed by Martin Roesch. Can sniff packets and spool to disk with 2GB file rollover, or rewrite packets to a second interface acting as a soft tap. Licensed under GPL v2 with Cisco clarifications.

Quantifiable outcome

  • 5 million+ software downloads
  • +3 more outcomes

Companies that use Snort

Customer profile

Named customers1 record

Segments4 records

Ideal customer profiles3 records

Snort technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration10 records

AI capability3 records

Feature9 records

Snort partnerships and signals

Strategic signal

Scale indicators6 records

Recent moves6 records

Expansion highlights6 records

Snort competitors and assessment

Company assessment

Direct peers

  • Suricata: Open-source network IDS/IPS/NSM engine developed by the OISF foundation; directly competes with Snort on rule-based and protocol-aware network detection, and is positioned by many as the higher-performance alternative in the same deployment scenarios.
  • Zeek (formerly Bro): Open-source network security monitor focused on rich semantic traffic analysis and behavioral logs; commonly deployed alongside or instead of Snort for network detection, sharing the same target users (SOC analysts, IDS operators).
  • Corelight: Commercial vendor built on Zeek that delivers enterprise-grade network detection and response appliances and SaaS; competes for the same enterprise budget as Snort-based deployments, particularly where richer analytics are valued over pure signature matching.
  • Security Onion: Linux distribution for IDS, NSM, and log management that bundles Snort, Suricata, Zeek, and Elastic Stack; a closely adjacent open-source platform that competes for the same SOC/network-security-monitoring buyer, where Snort is one of several engines it ships.

Broad incumbents

  • Cisco Secure Firewall (Firepower / Firepower Threat Defense): Cisco's commercial NGFW product line that runs Snort under the hood for IPS/IDS; competes with Snort-as-standalone in enterprises that prefer an integrated appliance, and is the primary vehicle through which Cisco monetizes Snort technology.
  • Palo Alto Networks Next-Generation Firewalls: Market-leading NGFW vendor with App-ID and Threat Prevention; competes with Snort-based IPS deployments in enterprise network security, offering an integrated alternative to standalone open-source IPS.
  • Fortinet FortiGate: Broad incumbent NGFW/UTM vendor with integrated IPS, sandboxing, and SD-WAN; competes with Snort in mid-market and enterprise network security, often replacing or being evaluated against Snort in greenfield deployments.
  • Check Point Quantum Security Gateway: Enterprise NGFW and threat prevention platform; competes with Snort-based IPS in enterprise perimeter and data-center deployments, often as part of broader Check Point Infinity architecture.

Emerging players

  • Darktrace: AI-driven network detection and response vendor using unsupervised machine learning for anomaly-based threat detection; competes with Snort for the network detection budget, especially in enterprises prioritizing behavioral over signature-based detection.
  • Vectra AI: Network detection and response platform using AI to surface attacker behaviors across cloud, SaaS, and on-prem networks; overlaps with Snort's use case in SOC workflows, particularly where ML-driven triage is preferred over ruleset management.

Market position

Strengths4 records

Weaknesses4 records

Competitive moat6 records

Key risks6 records

Key highlights6 records

Customer concentration

Snort social profiles

Digital presence

Snort financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Snort leadership team

Management profile

Number of profiles

Profiles3 records

Snort funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Snort M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Snort

What does Snort do?

Snort is an open-source network intrusion prevention system (IPS) that performs real-time traffic analysis and packet logging on IP networks using a rule-based detection engine. The software is freely distributed under GPL v2 and is available alongside tiered rulesets (free Community Ruleset, free Registered Rule Set, and paid Talos Subscriber Rule Set) for detecting exploits, zero-day threats, and anomalous traffic. Snort is deployed by enterprises, individual users, MSSPs, and OEMs, and is also sold under a commercial Snort Integrator License for bundling in third-party products.

Is Snort a public or private company?

Snort is a private company. It is classified as corporate owned and is currently operating.

When was Snort founded?

Snort was founded in 1998. It employs 51 to 100 people.

Where is Snort based?

Snort is headquartered in Columbia, United States, in the North America region.

How does Snort make money?

Four revenue lines are on record. Snort Subscriber Rule Set Subscription is the primary driver. The others are commercial Rule License, snort Integrator License and community Ruleset.

Who are Snort's main competitors?

Direct peers on record are Suricata, Zeek (formerly Bro), Corelight and Security Onion. Broad incumbents are Cisco Secure Firewall (Firepower / Firepower Threat Defense), Palo Alto Networks Next-Generation Firewalls, Fortinet FortiGate and Check Point Quantum Security Gateway. Emerging players are Darktrace and Vectra AI.

Does Snort have an API?

Yes. Snort provides an API mechanism through Oinkcodes - unique API keys associated with user accounts that allow programmatic download of rule packages. Subscribers use their oinkcode to download the latest rules via URL: https://www.snort.org/rules/?oinkcode=. PulledPork (a Perl-based tool) is the recommended helper script for automating rule downloads using the oinkcode API, featuring automatic MD5 verification, full handling of Shared Object rules, and generation of so_rule stub files. Community rules are available without authentication at https://www.snort.org/rules/community. Developer documentation is at www.snort.org/oinkcodes.

What industry is Snort in?

Snort's product category is Network Intrusion Prevention System (IPS). Its primary akta.pro industry code is HDAFAFAA, Next-Generation Firewalls (NGFW), with a secondary code of HDADABAA, Next-Gen Firewalls (NGFW) & UTM.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals