Home/Network IDS rules
IDS / IPS

Network IDS rules

279 rules · linked to T1486 · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. Expand a rule to view its source link.

Rules

50 shown of 279
et-open command-and-control
sid 2024290 format suricata
sid 2024298 format suricata
sid 2024300 format suricata
et-open command-and-control
ET MALWARE MSIL/EasyLocker Ransomware CnC Activity
sid 2024320 format suricata
et-open trojan-activity
ET MALWARE UIWIX Ransomware .onion Payment Domain (4ujngbdqqm6t2c53)
sid 2024323 format suricata
et-open command-and-control
sid 2024340 format suricata
et-open trojan-activity
ET MALWARE Executioner Ransomware Reporting Infection via SMTP
sid 2024351 format suricata
et-open command-and-control
ET MALWARE MSIL/Unk.HT-Based Ransomware CnC Checkin
sid 2024352 format suricata
sid 2024439 format suricata
sid 2024440 format suricata
et-open command-and-control
ET MALWARE Win32/Striked Ransomware CnC Checkin
sid 2024465 format suricata
et-open command-and-control
ET MALWARE Observed DNS Query to Known Fenrir Ransomware CnC Domain
sid 2024467 format suricata
et-open command-and-control
ET MALWARE Observed Malicious DNS Query (Reyptson Ransomware CnC)
sid 2024469 format suricata
et-open command-and-control
ET MALWARE Shifr Ransomware CnC DNS Query (v5t5z6a55ksmt3oh)
sid 2024491 format suricata
et-open command-and-control
ET MALWARE Shifr Ransomware CnC DNS Query (ojdue4474qghybjb)
sid 2024492 format suricata
sid 2024516 format suricata
sid 2024517 format suricata
sid 2024518 format suricata
sid 2024519 format suricata
sid 2024520 format suricata
sid 2024521 format suricata
sid 2024522 format suricata
sid 2024523 format suricata
sid 2024524 format suricata
sid 2024525 format suricata
et-open trojan-activity
sid 2024603 format suricata
et-open command-and-control
ET MALWARE ApolloLocker Ransomware CnC Checkin
sid 2024666 format suricata
et-open command-and-control
ET MALWARE ApolloLocker Ransomware CnC Checkin 2
sid 2024667 format suricata
et-open trojan-activity
ET MALWARE BadRabbit Ransomware Activity Via WebDAV (cscc)
sid 2024905 format suricata
et-open trojan-activity
ET MALWARE BadRabbit Ransomware Activity Via WebDAV (infpub)
sid 2024906 format suricata
et-open command-and-control
ET MALWARE SAD Ransomware CnC Activity
sid 2024954 format suricata
sid 2024981 format suricata
sid 2024982 format suricata
sid 2024983 format suricata
sid 2025143 format suricata
et-open trojan-activity
ET MALWARE MoneroPay Ransomware Payment Activity
sid 2025204 format suricata
et-open command-and-control
ET MALWARE Win32/GandCrab Ransomware CnC Activity
sid 2025254 format suricata
et-open command-and-control
ET MALWARE Shurl0ckr Ransomware CnC (kdvm5fd6tn6jsbwh .onion .to in DNS Lookup)
sid 2025332 format suricata
et-open trojan-activity
ET MALWARE Observed Princess Ransomware Payment Domain (royal25fphqilqft in DNS Lookup)
sid 2025404 format suricata
et-open command-and-control
ET MALWARE Observed GandCrab Ransomware CnC/IP Check Domain (politiaromana .bit in DNS Lookup)
sid 2025405 format suricata
et-open command-and-control
ET MALWARE Observed GandCrab Ransomware CnC/IP Check Domain (malwarehunterteam .bit in DNS Lookup)
sid 2025406 format suricata
et-open command-and-control
ET MALWARE Observed GandCrab Ransomware CnC/IP Check Domain (gdcb .bit in DNS Lookup)
sid 2025407 format suricata
et-open trojan-activity
ET MALWARE Observed GandCrab Ransomware Domain (ransomware .bit in DNS Lookup)
sid 2025452 format suricata
et-open trojan-activity
ET MALWARE Observed GandCrab Ransomware Domain (zonealarm .bit in DNS Lookup)
sid 2025453 format suricata
et-open trojan-activity
ET MALWARE Observed GandCrab Ransomware Domain (chlenaverasiskihe .sex in DNS Lookup)
sid 2025454 format suricata
et-open command-and-control
ET MALWARE Win32/GandCrab Ransomware CnC Activity M2
sid 2025455 format suricata
sid 2025486 format suricata
et-open trojan-activity
ET MALWARE Observed GandCrab Ransomware Domain (carder .bit in DNS Lookup)
sid 2025546 format suricata
et-open trojan-activity
ET MALWARE Likely GandCrab Ransomware Domain in HTTP Host M1
sid 2025547 format suricata
et-open trojan-activity
ET MALWARE Likely GandCrab Ransomware Domain in HTTP Host M2
sid 2025548 format suricata
Showing 101-150 of 279
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin