Updated Date: 07/07/2026
Snort rule reference
This document includes the Snort commands that are currently supported when writing Snort rules.
Protocol Anomaly Inspection supports a subset of Snort rules. See the Snort users manual for more information. Snort rules can be written as pcre (perl-compatible regular expressions). Negation (!) is not supported.
The following parameters are supported when using the content and pcre commands. See content and pcre.
- nocase
- depth
- offset
- distance
- within
- http_client_body
- http_cookie
- http_header
- http_method
- http_uri
All parameters for byte_test are supported except dce and bitmask. See the byte_test.
All parameters for byte_jump are supported except dce, multiplier, align, post_offset, and bitmask. See byte_jump.
The following parameter is supported in metadata. See metadata.
- service
The following parameters are supported in reference. See reference.
- url
- cve
- bugtraq
The following additional parameters are supported.
- Description
- Attack Type
- Direction
- Revision
The following parameters are added:
- protocol
- accuracy
- risk
- systems
- documentation
- last_updated
- performance_impact