Tool
Network IDS
Suricata / ET-open
48,683 rules · network intrusion-detection signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.
◈
Rules
50 shown of 48,683
et-open
not-suspicious
ET POLICY Cisco Device in Config Mode
et-open
not-suspicious
ET POLICY Cisco Device New Config Built
et-open
policy-violation
ET CHAT Yahoo IM voicechat
et-open
policy-violation
ET CHAT Yahoo IM file transfer request
et-open
successful-admin
ET POLICY Dameware Remote Control Service Install
et-open
pup-activity
ET ADWARE_PUP Websearch.com Spyware
et-open
misc-activity
ET INFO RDP - Response To External Host
et-open
policy-violation
ET CHAT Yahoo IM Unavailable Status
et-open
pup-activity
ET ADWARE_PUP Searchmeup Spyware Install (prog)
et-open
pup-activity
ET ADWARE_PUP Searchmeup Spyware Receiving Commands
et-open
pup-activity
ET ADWARE_PUP Searchmeup Spyware Install (systime)
et-open
pup-activity
ET ADWARE_PUP Searchmeup Spyware Install (mstask)
et-open
pup-activity
ET ADWARE_PUP Tibsystems Spyware Download
et-open
pup-activity
ET ADWARE_PUP Outerinfo.com Spyware Advertising Campaign Download
et-open
pup-activity
ET ADWARE_PUP Outerinfo.com Spyware Activity
et-open
pup-activity
ET ADWARE_PUP Internet Optimizer Activity User-Agent (IOKernel)
et-open
misc-activity
ET EXPLOIT NTDump Session Established Reg-Entry port 445
et-open
misc-activity
ET EXPLOIT NTDump.exe Service Started port 445
et-open
misc-activity
ET SCAN Behavioral Unusual Port 137 traffic Potential Scan or Infection
et-open
misc-activity
ET SCAN Behavioral Unusual Port 135 traffic Potential Scan or Infection
et-open
misc-activity
ET SCAN Behavioral Unusual Port 1434 traffic Potential Scan or Infection
et-open
misc-activity
ET SCAN Behavioral Unusual Port 1433 traffic Potential Scan or Infection
et-open
trojan-activity
ET ATTACK_RESPONSE Zone-H.org defacement notification
et-open
web-application-attack
ET ACTIVEX winhlp32 ActiveX control attack - phase 1
et-open
web-application-attack
ET ACTIVEX winhlp32 ActiveX control attack - phase 2
et-open
web-application-attack
ET ACTIVEX winhlp32 ActiveX control attack - phase 3
Showing 51-100 of 48,683