IDS Rule Converter
Stop guessing whether a converted IDS rule still means the same thing.
IDS Rule Converter is a secure, loss-aware, one-file Python toolkit for parsing, validating, analyzing, comparing, and converting Snort and Suricata rules. It defaults to refusing uncertain translations instead of silently dropping or weakening detection logic.
The runtime has no third-party Python dependencies. Copy
snort_suricata_rule_converter.py to a system with Python 3.10 or newer and run
it directly.
Version 4.0.1 is the current release. Download the verified standalone Python runtime or the deterministic documentation ZIP. The release page also provides the SPDX SBOM, SHA-256 checksums, release evidence, and GitHub provenance. See RELEASING.md for the exact artifact and publication gates.
Why this tool is different
Rule conversion is not a keyword replacement problem. Sticky buffers, content modifier placement, service declarations, application protocols, regular expressions, and engine-specific actions all affect detection behavior.
IDS Rule Converter provides:
- Ordered parsing that preserves repeated options and content modifier context
- Strict, fail-safe conversion between Snort 2, Snort 3, and Suricata 8
- Explicit rejection files and machine-readable reports for unsafe rules
- Native JSON and SARIF output for automation and code scanning systems
- Duplicate SID, conflicting SID, keyword, protocol, and action analysis
- Semantic ruleset comparison by GID, SID, revision, and fingerprint
- Offline Panorama IPS Signature Converter 2.0.4 compatibility preflight
- Safe download support for allowlisted Cisco Talos community feeds
- Archive defenses against traversal, links, special files, duplicate paths, encrypted ZIP entries, Windows device names, and decompression abuse
- Atomic output writes, overwrite refusal, and input replacement protection
- No telemetry and no implicit network access
Quick start
python snort_suricata_rule_converter.py --help
python snort_suricata_rule_converter.py validate input.rules
python snort_suricata_rule_converter.py analyze input.rules --output analysis.json
Convert a Snort 3 ruleset to Suricata. Strict mode is the default, so no ruleset is written if any rule has an unsafe or unverified mapping.
python snort_suricata_rule_converter.py convert input.rules --source-dialect snort3 --target suricata --output converted.rules --report conversion.json
To export only the verified subset, preserve every rejected source rule, and receive a detailed report:
python snort_suricata_rule_converter.py convert input.rules --source-dialect snort3 --target suricata --output accepted.rules --allow-partial --rejected-output rejected.rules --report conversion.json
An intentional partial result exits with code 2 so automation cannot mistake it for a complete conversion.
Strict and reviewed partial results
Constructed test data. Strict mode writes no converted ruleset when one mapping is unsafe. An explicit partial export preserves accepted rules, rejected source rules, and the report as one review set. Native target validation is still required.
Commands
| Command | Purpose |
|---|---|
validate |
Parse rules and report structural or identifier problems |
analyze |
Inventory rules, keywords, actions, protocols, duplicates, and conflicts |
convert |
Convert to Snort 2, Snort 3, Suricata, or structured JSON |
panorama-preflight |
Check and batch rules for Panorama plugin 2.0.4 |
diff |
Compare two rulesets by GID and SID |
list-sources |
Show built-in HTTPS feed definitions |
fetch |
Download and optionally extract an allowlisted rule feed safely |
See QUICK_REFERENCE.md for copy-ready examples.
Conversion safety model
The default behavior is intentionally conservative:
- The complete input must parse successfully.
- Each rule is checked against the declared target dialect.
- Verified transformations preserve option order and buffer context.
- A rule with an unsafe mapping is rejected, not approximated.
- Strict conversion writes nothing when any rule is rejected.
- Partial conversion requires both a rejection file and a JSON report.
- Unknown target keywords require the explicit
--allow-unverifiedopt-out.
Important verified transformations include Snort 3 and Suricata HTTP sticky
buffers, Snort 2 HTTP content modifiers, safe service mappings, TLS protocol
naming, selected SIP options, bufferlen to bsize, stream_size syntax,
fast-pattern offsets, and compatible tag syntax.
The converter rejects ambiguous multi-service rules, unsupported target actions, conflicting application protocols, unsafe buffer arguments, packet and application-layer conflicts, unsupported BER and DCE options, and other cases where equivalence has not been established.
Always run the target engine's native configuration test before deployment. Successful parsing proves that an engine accepts a rule. It does not prove that every rule will detect identical traffic under every engine configuration.
Panorama preflight
The Panorama command performs an offline compatibility review for IPS Signature Converter plugin 2.0.4. It checks documented action, protocol, condition, PCRE, threshold, reference, case-sensitivity, negation, and positional limits. Accepted source rules are divided into batches of no more than 100 rules and 8 MB.
python snort_suricata_rule_converter.py panorama-preflight input.rules --output-dir panorama-review
The tool never connects to Panorama and never uploads a rule.
Safe feed retrieval
Network access occurs only when fetch is explicitly invoked. Built-in sources
use HTTPS and an exact hostname allowlist. Redirects outside that allowlist are
refused.
python snort_suricata_rule_converter.py list-sources
python snort_suricata_rule_converter.py fetch --source snort3-community --output-dir downloads --extract
The downloaded archive, SHA-256 metadata, and extracted files are local outputs. Rules remain subject to their provider's terms and are not part of this project's Apache 2.0 license.
Test evidence
The 4.0.1 release-readiness tree contains 64 automated tests covering parsing, conversion, reports, Panorama checks, overwrite controls, URL and redirect policy, malicious archives, repository text policy, and deterministic release construction. CI exercises Python 3.10 through 3.14 on Linux, Python 3.12 on Windows and macOS, and both conversion directions against pinned Snort 3.10.0.0 and Suricata 8.0.6 containers.
The larger 4,017-rule Cisco Talos community corpus was validated for version 4.0.0. Snort accepted the full same-dialect round trip with zero warnings. The fail-safe Suricata conversion accepted 3,762 rules, rejected 255 with recorded reasons, and passed native validation with zero errors. Suricata emitted 71 nonfatal duplicate-buffer warnings for source patterns that intentionally revisit an earlier sticky buffer.
Version 4.0.1 changes output-file race handling, feed URL validation, repository controls, and release construction. It does not change conversion semantics. The large third-party corpus has not been rerun for the candidate, so its result is kept explicitly separate from the current hosted native-fixture checks. Full commands, container digests, and scope are recorded in docs/TESTING.md.
Exit codes
| Code | Meaning |
|---|---|
0 |
Operation completed without blocking findings |
1 |
Operational failure, unsafe path, network failure, or invalid invocation |
2 |
Validation findings, conflicts, rejected rules, or an intentional partial result |
130 |
Interrupted by the operator |
Development
python -m pip install -r requirements-dev.txt
python -m ruff format --check .
python -m ruff check .
python -m bandit -q -r snort_suricata_rule_converter.py scripts
python -m pip_audit -r requirements-dev.txt
python -m unittest discover -s tests -v
The production runtime remains one file. Tests, documentation, and repository automation are separate so the executable itself stays portable.
Security and privacy
- Rule files are processed locally.
- The tool contains no credentials, tokens, account IDs, or environment-specific resource names.
- Output files are UTF-8 and written atomically.
- Existing outputs are refused unless
--forceis supplied. --forcecannot replace an input file.- Report suspected vulnerabilities through the private process in SECURITY.md.
License
The converter, tests, and project documentation are licensed under the Apache License 2.0. Third-party rules, vendor documents, and downloaded feeds are not redistributed by this repository and retain their original terms.
Snort is a registered trademark of Cisco. Suricata is a registered trademark of the Open Information Security Foundation. This project is independent and is not endorsed by either organization.
Metadata
Release files for ids-rule-converter 4.0.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ids_rule_converter-4.0.2.tar.gz | 215.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ids_rule_converter-4.0.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 355.8 kB
Release files / ids_rule_converter-4.0.2.tar.gz
| Download URL | ids_rule_converter-4.0.2.tar.gz |
|---|---|
| Size | 215.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
9e5b74b741ab9425799b18ceead72dc48d71688ff38fe9ded5c032a20fb451ce
|
|
BLAKE2b-256 checksum How to use checksums |
1f2867df86e63189f75196747abbc2ab9b87825c9c00b46e31587658d620c385
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency logRelease files / ids_rule_converter-4.0.2-py3-none-any.whl
| Download URL | ids_rule_converter-4.0.2-py3-none-any.whl |
|---|---|
| Size | 140.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6522de230ae1032a560363ff1887dbcc744888ccfd6e738f8b10cb8d48739cc2
|
|
BLAKE2b-256 checksum How to use checksums |
a34006e304644990bf74f0af8bb12729ab05b09d4e91357c3bf15db3f4340bf9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency log