IDS (Intrusion Detection)

The QROS IDS deploys Suricata and Snort on your edge hosts with tuned rule sets and pushes alerts to the SOC monitoring stack. Every alert can feed the IPS deny list, so detection becomes prevention without manual triage.

QROS · IDS · Suricata + Snort23 alerts
7critical
16high
Alerts (last hour)
ET POLICY Tor exit185.220.101.xcrit
ET EXPLOIT log4j RCE45.155.205.xhigh
ET SCAN nmap91.243.59.xhigh
ET INFO SSH brute193.32.162.xmed
Rule sources
ET/OpenSuricata built-inSnort communitycustom

Suricata + Snort

QROS deploys both engines so you get Suricata's high-throughput multi-pattern matching and Snort's rule ecosystem. Rule sets are pulled from Emerging Threats Open, the Suricata built-in set, the Snort community rules and your own custom rules, with a tuned threshold per host to cut noise.

Detection to prevention

Alerts stream into OpenSearch and, when a source crosses the configured severity, are pushed to the IPS deny list automatically. You keep full visibility in SOC monitoring while the edge stops the attack.

FAQ

Why run both Suricata and Snort?

Suricata gives high-throughput multi-pattern matching and HTTP/DNS/TLS logging; Snort brings its large rule ecosystem. Running both maximizes coverage. QROS deploys and tunes both over Ansible.

Do alerts block traffic automatically?

Only when you enable it. Alerts always stream to SOC monitoring; sources that cross a severity threshold you set are pushed to the IPS deny list so detection becomes prevention.

Try this service with QROS

Explore now →