I would think that if the admins are looking at the IDS logs they will detect your probing for what IDS they have before you get a chance to use said information. Makes it somewhat pointless, either they are looking at their logs and see your probes for what IDS they use, or there aren’t paying attention to what their IDS reports so it does not matter anyway. Still, interesting to know about Snort and "reacts".