Home/Network IDS rules
IDS / IPS

Network IDS rules

4,992 rules · linked to T1568 · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. Expand a rule to view its source link.

Rules

50 shown of 4,992
et-open bad-unknown
ET INFO DYNAMIC_DNS Query to Abused Domain *.mooo.com
sid 2015633 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to Abused Domain *.mooo.com
sid 2015634 format suricata
sid 2018212 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to a *.sytes.net Domain
sid 2018219 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to a *.ddns.info Domain
sid 2018220 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to a *.ddns.name Domain
sid 2018221 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to a *.mrbasic.com Domain
sid 2018365 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS Query to a *.mrbasic.com Domain
sid 2018366 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to a *.dnsalias.ru Domain
sid 2022377 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to a *.dnsip.ru Domain
sid 2022378 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to a *.dyn-dns.ru Domain
sid 2022379 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to a *.dns-free.ru Domain
sid 2022380 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS Query to a Suspicious *.dnsip.ru Domain
sid 2022382 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS Query to a Suspicious *.dyn-dns.ru Domain
sid 2022383 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS Query to a Suspicious dynapoint.pw Domain
sid 2022876 format suricata
et-open bad-unknown
ET INFO Observed DNS Query to .myq-see .com DDNS Domain
sid 2025560 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS Query to *.myddns.me Domain
sid 2027287 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to a *.myddns.me Domain
sid 2027288 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS Query to *.autoddns .com Domain
sid 2027299 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS HTTP Request to a *.autoddns.com Domain
sid 2027300 format suricata
et-open bad-unknown
ET INFO DYNAMIC_DNS Query to a *.addns .org Domain
sid 2032896 format suricata
sid 2035961 format suricata
sid 2035962 format suricata
sid 2035963 format suricata
sid 2035964 format suricata
sid 2035965 format suricata
sid 2035968 format suricata
sid 2035969 format suricata
sid 2035970 format suricata
sid 2035971 format suricata
sid 2035972 format suricata
sid 2035973 format suricata
sid 2035974 format suricata
sid 2035975 format suricata
sid 2035976 format suricata
sid 2035977 format suricata
sid 2035978 format suricata
sid 2035979 format suricata
sid 2035980 format suricata
sid 2035981 format suricata
sid 2035982 format suricata
sid 2035983 format suricata
sid 2035984 format suricata
sid 2035985 format suricata
sid 2035986 format suricata
sid 2035987 format suricata
sid 2035988 format suricata
sid 2035989 format suricata
sid 2035990 format suricata
sid 2035991 format suricata
Showing 51-100 of 4,992
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin