Capsule8, now part of Sophos vs. Snort

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Capsule8, now part of Sophos
Score 10.0 out of 10
N/A
Capsule8 from Sophos (acquired 2021) provides attack protection for enterprise Linux -- whether containerized, virtualized, or bare metal. It is an EDR solution the vendor presents as performant and purpose built Linux detection that protects against threats, provides consistent visibility and ensures availability for production infrastructure in hybrid muti-cloud environments regardless of workload.N/A
Snort
Score 8.4 out of 10
N/A
Sourcefire developed Snort, an open source intrusion prevention system capable of real-time traffic analysis and packet logging. Snort was acquired (and is now supported) by Cisco in 2013.N/A
Pricing
Capsule8, now part of SophosSnort
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Capsule8, now part of SophosSnort
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Capsule8, now part of SophosSnort
Best Alternatives
Capsule8, now part of SophosSnort
Small Businesses
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 3.7 out of 10
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 3.7 out of 10
Medium-sized Companies
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
Enterprises
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Capsule8, now part of SophosSnort
Likelihood to Recommend
-
(0 ratings)
8.1
(0 ratings)
User Testimonials
Capsule8, now part of SophosSnort
Likelihood to Recommend
No answers on this topic
If a colleague was looking to tighten down their network I can easily recommend Snort to them. It gives you some more peace of mind knowing that its always scanning traffic for malicious looking code. Even things your major firewalls and security hardware might miss, Snort has picked up. Its an easy recommendation for me.
Read full review
Pros
No answers on this topic
  • The threat intelligence from Cisco TALOS is unparalleled. This is grafted into the Sourcefire application which greatly improves security visibility. With this there are a lot of groups that you can use for white listing or blacklisting, knowing its being updated in the background without additional work from you.
  • Flexible. Instead of putting a traditional firewall inline you can put a source fire appliance (or firewall with sourcefire on-board) to not only block/allow traffic, but if you insights into it, and do some forms of threat scoring.
  • In depth information. Sometimes a bit overwhelming, but you are able to do more than just see alerts, you can view the full information and packets that lead to the conclusion, though the conclusion is prepared in advance for you.
Read full review
Cons
No answers on this topic
  • There are plenty of false positives in the logs, but no problems noticed related to them.
Read full review
Alternatives Considered
No answers on this topic
Snort was chosen mainly for the ease and cost. With Snort we was able to set up in a matter of minutes without any professional services needed. If you are used to packet tracing the old fashion way, this is the product for you.
Read full review
Return on Investment
No answers on this topic
  • The Sourcefire deployment has been very good at actively blocking threats that would have potentially caused loss or compromise.
  • It has given us great visibility to our network.
Read full review
ScreenShots