Home/Detection rules/Suricata / ET-open
Tool
Network IDS

Suricata / ET-open

978 rules · network intrusion-detection signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.

Rules

50 shown of 978
sid 2009486 format suricata
et-open targeted-activity
sid 2016398 format suricata
sid 2016431 format suricata
sid 2016434 format suricata
sid 2016435 format suricata
sid 2016436 format suricata
sid 2016437 format suricata
sid 2016438 format suricata
sid 2016439 format suricata
sid 2016449 format suricata
sid 2016451 format suricata
sid 2016452 format suricata
sid 2016455 format suricata
sid 2016456 format suricata T1041 ↗
sid 2016457 format suricata T1041 ↗
sid 2016459 format suricata
sid 2016461 format suricata
et-open targeted-activity
sid 2016462 format suricata
et-open targeted-activity
sid 2016464 format suricata
et-open targeted-activity
sid 2016465 format suricata
et-open targeted-activity
sid 2016466 format suricata
et-open targeted-activity
sid 2016467 format suricata
et-open targeted-activity
sid 2016468 format suricata
et-open targeted-activity
sid 2016469 format suricata
et-open targeted-activity
sid 2016470 format suricata
sid 2016471 format suricata
sid 2016472 format suricata
et-open targeted-activity
ET MALWARE CommentCrew UGX Backdoor initial connection
sid 2016474 format suricata
et-open targeted-activity
ET MALWARE CommentCrew downloader without user-agent string exe download without User Agent
sid 2016475 format suricata
et-open targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications get system
sid 2016476 format suricata T1071 ↗
et-open targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications html return 1
sid 2016477 format suricata T1071 ↗
et-open targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications sleep
sid 2016478 format suricata T1071 ↗
et-open targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications sleep2
sid 2016479 format suricata T1071 ↗
et-open targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications sleep3
sid 2016480 format suricata T1071 ↗
et-open targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications sleep5
sid 2016482 format suricata T1071 ↗
et-open targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications download client.png
sid 2016483 format suricata T1071 ↗
et-open targeted-activity
ET MALWARE CommentCrew Possible APT crabdance backdoor base64 head 2
sid 2016484 format suricata
et-open targeted-activity
ET MALWARE CommentCrew Possible APT crabdance backdoor base64 head
sid 2016485 format suricata
et-open targeted-activity
ET MALWARE CommentCrew Possible APT backdoor stage 2 download base64 update.gif
sid 2016486 format suricata
et-open targeted-activity
ET MALWARE CommentCrew Possible APT backdoor download logo.png
sid 2016487 format suricata
et-open targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications get command client key
sid 2016488 format suricata T1071 ↗
et-open targeted-activity
sid 2016568 format suricata T1041 ↗
sid 2016569 format suricata
sid 2016570 format suricata
sid 2016571 format suricata
et-open targeted-activity
sid 2016572 format suricata
et-open targeted-activity
sid 2016573 format suricata
et-open targeted-activity
sid 2016579 format suricata
sid 2016713 format suricata
sid 2016727 format suricata
Showing 1-50 of 978