Tool
Network IDS
Suricata / ET-open
4,606 rules · network intrusion-detection signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.
◈
Rules
50 shown of 4,606
et-open
misc-activity
ET POLICY Outbound Multiple Non-SMTP Server Emails
et-open
misc-activity
ET INFO IRC Nick change on non-standard port
et-open
misc-activity
ET CHAT IRC authorization message
et-open
misc-activity
ET EXPLOIT NTDump Session Established Reg-Entry port 139
et-open
misc-activity
ET EXPLOIT NTDump.exe Service Started port 139
et-open
misc-activity
et-open
misc-activity
ET INFO RDP - Response To External Host
et-open
misc-activity
ET EXPLOIT NTDump Session Established Reg-Entry port 445
et-open
misc-activity
ET EXPLOIT NTDump.exe Service Started port 445
et-open
misc-activity
ET SCAN Behavioral Unusual Port 137 traffic Potential Scan or Infection
et-open
misc-activity
ET SCAN Behavioral Unusual Port 135 traffic Potential Scan or Infection
et-open
misc-activity
ET SCAN Behavioral Unusual Port 1434 traffic Potential Scan or Infection
et-open
misc-activity
ET SCAN Behavioral Unusual Port 1433 traffic Potential Scan or Infection
et-open
misc-activity
ET WEB_CLIENT Encoded javascriptdocument.write - usually hostile
et-open
misc-activity
ET CHAT IRC USER command
et-open
misc-activity
ET CHAT IRC NICK command
et-open
misc-activity
ET CHAT IRC JOIN command
et-open
misc-activity
ET CHAT IRC PRIVMSG command
et-open
misc-activity
ET CHAT IRC PING command
et-open
misc-activity
ET CHAT IRC PONG response
et-open
misc-activity
ET POLICY Inbound Frequent Emails - Possible Spambot Inbound
et-open
misc-activity
ET SCAN Rapid POP3 Connections - Possible Brute Force Attack
et-open
misc-activity
ET SCAN Rapid POP3S Connections - Possible Brute Force Attack
et-open
misc-activity
ET SCAN Rapid IMAP Connections - Possible Brute Force Attack
et-open
misc-activity
ET SCAN Rapid IMAPS Connections - Possible Brute Force Attack
et-open
misc-activity
ET POLICY Microsoft TEREDO IPv6 tunneling
et-open
misc-activity
et-open
misc-activity
ET POLICY trymedia.com User-Agent (Macrovision_DM)
et-open
misc-activity
ET SCAN ICMP @hello request Likely Precursor to Scan
et-open
misc-activity
ET WEB_CLIENT PROPFIND Flowbit Set
et-open
misc-activity
ET POLICY Microsoft user-agent automated process response to automated request
et-open
misc-activity
ET INFO DYNAMIC_DNS Query to *.dyndns. Domain
Showing 1-50 of 4,606