Home/Network IDS rules
IDS / IPS

Network IDS rules

52,377 rules · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. Expand a rule to view its source link.

Rules

50 shown of 52,377
et-open pup-activity
ET ADWARE_PUP Zango Seekmo Bar Spyware User-Agent (Seekmo Toolbar)
sid 2003397 format suricata
et-open pup-activity
ET ADWARE_PUP Morpheus Spyware Install User-Agent (SmartInstaller)
sid 2003398 format suricata
et-open pup-activity
ET ADWARE_PUP Freeze.com Spyware User-Agent (YourScreen123)
sid 2003405 format suricata
et-open pup-activity
ET ADWARE_PUP searchenginebar.com Spyware User-Agent (RX Bar)
sid 2003407 format suricata
et-open pup-activity
ET ADWARE_PUP clickspring.com Spyware Install User-Agent (CS Fingerprint Module)
sid 2003425 format suricata
et-open pup-activity
ET ADWARE_PUP Outerinfo.com Spyware Checkin
sid 2003426 format suricata
et-open pup-activity
ET ADWARE_PUP Surfaccuracy.com Spyware Install User-Agent (SF Installer)
sid 2003428 format suricata
et-open pup-activity
ET ADWARE_PUP Dropspam.com Spyware Install User-Agent (DSInstall)
sid 2003439 format suricata
et-open pup-activity
ET ADWARE_PUP Dropspam.com Spyware Reporting
sid 2003440 format suricata
et-open pup-activity
ET ADWARE_PUP Deskwizz.com Spyware Install INI Download
sid 2003445 format suricata
et-open policy-violation
ET POLICY Metacafe.com Social Site Access
sid 2003457 format suricata
et-open policy-violation
ET POLICY Orkut.com Social Site Access
sid 2003458 format suricata
sid 2003464 format suricata
sid 2003465 format suricata
et-open web-application-attack
sid 2003466 format suricata
et-open policy-violation
ET POLICY AOL Toolbar User-Agent (AOLToolbar)
sid 2003469 format suricata
et-open pup-activity
ET USER_AGENTS Suspicious User-Agent (Updater)
sid 2003470 format suricata
sid 2003481 format suricata
sid 2003482 format suricata
sid 2003486 format suricata
sid 2003489 format suricata
et-open bad-unknown
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
sid 2003492 format suricata
et-open pup-activity
ET ADWARE_PUP AskSearch Spyware User-Agent (AskSearchAssistant)
sid 2003493 format suricata
et-open pup-activity
ET ADWARE_PUP AskSearch Toolbar Spyware User-Agent (AskBar)
sid 2003496 format suricata
et-open pup-activity
ET ADWARE_PUP User-Agent (ms)
sid 2003497 format suricata
et-open pup-activity
ET ADWARE_PUP Gamehouse.com Related Spyware User-Agent (Sprout Game)
sid 2003498 format suricata
sid 2003501 format suricata
et-open pup-activity
ET ADWARE_PUP Toplist.cz Related Spyware Checkin
sid 2003505 format suricata
sid 2003527 format suricata
sid 2003528 format suricata
sid 2003532 format suricata
et-open web-application-activity
sid 2003535 format suricata
sid 2003555 format suricata
et-open pup-activity
ET ADWARE_PUP User-Agent (DIALER)
sid 2003566 format suricata
sid 2003570 format suricata
et-open pup-activity
ET ADWARE_PUP Security-updater.com Spyware Posting Data
sid 2003576 format suricata
et-open pup-activity
ET USER_AGENTS Suspicious User-Agent (update)
sid 2003583 format suricata
et-open trojan-activity
ET MALWARE Downloader-5265/Torpig/Anserin/Sinowal Unique UA (MSID)
sid 2003590 format suricata
et-open trojan-activity
ET MALWARE W32.Virut.A joining an IRC Channel
sid 2003603 format suricata
et-open pup-activity
ET ADWARE_PUP EELoader Malware Packages User-Agent (EELoader)
sid 2003613 format suricata
et-open bad-unknown
ET INFO WinUpack Modified PE Header Inbound
sid 2003614 format suricata
et-open bad-unknown
ET INFO WinUpack Modified PE Header Outbound
sid 2003615 format suricata
et-open web-application-activity
sid 2003616 format suricata
et-open trojan-activity
ET USER_AGENTS Suspicious User-Agent outbound (bot)
sid 2003622 format suricata
sid 2003623 format suricata
et-open pup-activity
ET ADWARE_PUP dns-look-up.com Spyware User-Agent (KRSystem)
sid 2003625 format suricata
et-open bad-unknown
ET HUNTING Double User-Agent (User-Agent User-Agent)
sid 2003626 format suricata
sid 2003632 format suricata
et-open trojan-activity
ET MALWARE Suspicious User Agent Detected (RookIE) - Common with Downloaders
sid 2003635 format suricata
et-open pup-activity
ET ADWARE_PUP Sality Virus User Agent Detected (KUKU)
sid 2003636 format suricata
Showing 301-350 of 52,377
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin