#020 · Security ProfessionalsEpicLocked in

Martin Roesch

Author of Snort

Open-source intrusion detection, and the rule format everyone copied

Rating

89Impact score
Technical depth92
Defensive craft96
Research84
Influence91
FromUSA
Era1998–present

Domains

Intrusion detectionPacket analysisOpen source

Scouting report

Wrote Snort in 1998 as a lightweight packet sniffer, and it became the intrusion detection system that put IDS within reach of organisations that could never have bought one. Founded Sourcefire around it, which Cisco acquired in 2013. The Snort rule syntax outlived the product and is still how a large part of the industry writes network detections.

Curator’s note

A weekend tool that became the de facto standard for network detection.

Portrait

Painted from a photograph of Martin Roesch by Sourcefire press photo, supplied by the subject.

Sources