Firestorm is a Network Intrusion Detection sensor that is multi-threaded, fast, and is pluggable at almost every software architectural point. It also aims to support many open standards. Currently it is just a sensor, but plans are to support central correlation databases and an analyst console.
Current Features:
* Fully pluggable.
* Capture from libpcap files.
* Snort rule support.
* Almost as many matchers as snort.
* Support for IP, Ethernet and other common protocols.
* String match.
* TTL, and IP ID matchers.