Home/Network IDS rules
IDS / IPS

Network IDS rules

1,435 rules · linked to T1566 · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. Expand a rule to view its source link.

Rules

50 shown of 1,435
et-open credential-theft
ET PHISHING Successful Generic Credit Card Information Phish
sid 2015907 format suricata
et-open credential-theft
ET PHISHING Successful Generic PII Phish
sid 2015908 format suricata
et-open credential-theft
ET PHISHING Successful Bank of America Phish M1 Oct 01 2012
sid 2015909 format suricata
et-open credential-theft
ET PHISHING Possible Successful AOL Phish Nov 21 2012
sid 2015910 format suricata
et-open credential-theft
ET PHISHING Possible Successful Yahoo Phish Nov 21 2012
sid 2015911 format suricata
et-open credential-theft
ET PHISHING Possible Successful Gmail Phish Nov 21 2012
sid 2015912 format suricata
et-open credential-theft
ET PHISHING Possible Successful Hotmail Phish Nov 21 2012
sid 2015913 format suricata
et-open credential-theft
ET PHISHING Possible Successful Phish - Other Credentials Nov 21 2012
sid 2015914 format suricata
et-open credential-theft
ET PHISHING Possible Successful Generic SSN Phish
sid 2015952 format suricata
et-open credential-theft
ET PHISHING Successful PayPal Phish Nov 30 2012
sid 2015972 format suricata
et-open credential-theft
ET PHISHING Successful Google Account Phish Dec 04 2012
sid 2015980 format suricata
et-open credential-theft
ET PHISHING Successful PayPal Phish Dec 19 2012
sid 2016063 format suricata
et-open credential-theft
ET PHISHING Possible Successful Phish - Generic POST to myform.php Feb 01 2013
sid 2016327 format suricata
et-open social-engineering
ET PHISHING Possible Generic Phishing Landing Jul 12 2013
sid 2017135 format suricata
et-open credential-theft
ET PHISHING Possible Successful AOL Phish Nov 25 2013
sid 2017750 format suricata
et-open credential-theft
ET PHISHING Possible Successful Yahoo Phish Nov 25 2013
sid 2017751 format suricata
et-open credential-theft
ET PHISHING Possible Successful Gmail Phish Nov 25 2013
sid 2017752 format suricata
et-open credential-theft
ET PHISHING Possible Successful Remax Phish - Hotmail Creds Nov 25 2013
sid 2017753 format suricata
et-open credential-theft
ET PHISHING Possible Successful Phish - Other Credentials Nov 25 2013
sid 2017754 format suricata
et-open credential-theft
ET PHISHING Possible Successful Verified by Visa Phish Jan 30 2014
sid 2018044 format suricata
et-open trojan-activity
ET PHISHING Possible Phish - Mirrored Website Comment Observed
sid 2018302 format suricata
et-open credential-theft
ET PHISHING Successful iTunes Phish Mar 21 2014
sid 2018304 format suricata
et-open credential-theft
ET PHISHING Successful iTunes Phish Mar 21 2014
sid 2018305 format suricata
et-open bad-unknown
ET PHISHING Possible Phish - Saved Website Comment Observed
sid 2018334 format suricata
et-open credential-theft
ET PHISHING Successful AOL/PayPal Phish Nov 24 2014
sid 2019781 format suricata
et-open credential-theft
ET PHISHING Successful PayPal Phish Nov 24 2014
sid 2019782 format suricata
et-open credential-theft
ET PHISHING Successful Paypal Phish Nov 24 2014
sid 2019783 format suricata
et-open credential-theft
ET PHISHING Successful Paypal Phish Nov 24 2014
sid 2019784 format suricata
et-open credential-theft
ET PHISHING Successful Adobe Phish Jun 17 2015
sid 2021296 format suricata
et-open credential-theft
ET PHISHING Successful Google Drive Phish June 17 2015
sid 2021297 format suricata
et-open credential-theft
ET PHISHING Successful Dropbox Phish June 17 2015
sid 2021298 format suricata
et-open credential-theft
ET PHISHING Possible Successful Remax Phish - AOL Creds Jun 23 2015
sid 2021322 format suricata
et-open credential-theft
ET PHISHING Possible Successful Yahoo Phish Jun 23 2015
sid 2021323 format suricata
et-open credential-theft
ET PHISHING Possible Successful Remax Phish - Other Creds Jun 23 2015
sid 2021324 format suricata
et-open social-engineering
ET PHISHING Possible Generic Phishing Landing Jul 28 2015
sid 2021537 format suricata
et-open social-engineering
ET PHISHING Possible Generic Phishing Landing Jul 28 2015
sid 2021538 format suricata
et-open social-engineering
ET PHISHING Possible Generic Phishing Landing Jul 28 2015
sid 2021539 format suricata
et-open social-engineering
ET PHISHING Possible Generic Phishing Landing Jul 28 2015
sid 2021540 format suricata
et-open credential-theft
ET PHISHING Possible Successful Generic Phish - Credit Card
sid 2021692 format suricata
et-open credential-theft
ET PHISHING Possible Successful Generic Phish - Three Security Questions
sid 2021693 format suricata
et-open credential-theft
ET PHISHING Possible Successful Phish - Generic Status Messages Sept 11 2015
sid 2021761 format suricata
et-open credential-theft
ET PHISHING Successful Phish Outlook Credentials Oct 01 2015
sid 2021890 format suricata
et-open credential-theft
ET PHISHING Successful Paypal Account Phish Oct 30
sid 2022017 format suricata
et-open credential-theft
ET PHISHING Successful Paypal Account Phish 2015-10-30 2
sid 2022018 format suricata
et-open credential-theft
ET PHISHING Successful Paypal Account Phish 2015-10-30 3
sid 2022019 format suricata
et-open social-engineering
ET PHISHING Netsolhost SSL Proxying - Possible Phishing Nov 24 2015
sid 2022136 format suricata
et-open credential-theft
ET PHISHING Successful Google Drive Phish Dec 4 2015 M1
sid 2022217 format suricata
sid 2022374 format suricata
sid 2022487 format suricata
et-open credential-theft
ET PHISHING Successful Apple Phish M1 Feb 06 2016
sid 2022497 format suricata
Showing 1-50 of 1,435
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin