Home/Detection rules/Suricata / ET-open
Tool
Network IDS

Suricata / ET-open

48,683 rules · network intrusion-detection signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.
Using these IDS signatures
Deploy. Load them into a Suricata or Snort sensor and reload the ruleset; the sensor inspects traffic inline or from a tap or SPAN port and alerts (or drops) the moment a packet matches.
Adapt. Set the action per rule (alert vs drop), make sure the sensor actually sees the traffic in question - TLS payloads need decryption first - and silence noisy signatures that do not fit your network.
Scope. These catch malicious patterns on the wire: C2 beacons, exploit attempts, known-bad hosts. Pair them with endpoint and log detection, since encrypted or host-local activity never crosses the sensor.

Rules

50 shown of 48,683
sid 2005292 format suricata T1190 ↗
sid 2005294 format suricata T1190 ↗
sid 2005295 format suricata T1190 ↗
sid 2005296 format suricata T1190 ↗
sid 2005297 format suricata T1190 ↗
sid 2005298 format suricata T1190 ↗
sid 2005300 format suricata T1190 ↗
sid 2005301 format suricata T1190 ↗
sid 2005302 format suricata T1190 ↗
sid 2005303 format suricata T1190 ↗
et-open pup-activity
ET ADWARE_PUP Statblaster.com Spyware User-Agent (fetcher)
sid 2005318 format suricata
et-open trojan-activity
ET USER_AGENTS Suspicious User-Agent (MyAgent)
sid 2005320 format suricata
et-open pup-activity
ET ADWARE_PUP NavExcel Spyware User-Agent (NavHelper)
sid 2005321 format suricata
et-open pup-activity
ET ADWARE_PUP Spylocked Fake Anti-Spyware User-Agent (SpyLocked)
sid 2005322 format suricata
sid 2005328 format suricata T1190 ↗
sid 2005330 format suricata T1190 ↗
sid 2005332 format suricata T1190 ↗
sid 2005333 format suricata T1190 ↗
sid 2005334 format suricata T1190 ↗
sid 2005335 format suricata T1190 ↗
sid 2005336 format suricata T1190 ↗
sid 2005338 format suricata T1190 ↗
sid 2005339 format suricata T1190 ↗
sid 2005340 format suricata T1190 ↗
sid 2005341 format suricata T1190 ↗
Showing 1451-1500 of 48,683