Home/Network IDS rules
IDS / IPS

Network IDS rules

1,915 rules · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.

Rules

50 shown of 1,915
et-open exploit-kit
ET EXPLOIT_KIT Phoenix Exploit Kit VBscript download
sid 2011184 format suricata
et-open exploit-kit
ET EXPLOIT_KIT phoenix exploit kit - admin login page detected
sid 2011281 format suricata
et-open exploit-kit
ET EXPLOIT_KIT exploit kit x/load/svchost.exe
sid 2011906 format suricata
sid 2012841 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Redirection to driveby Page Home index.php
sid 2013436 format suricata
sid 2014147 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Sakura Exploit Kit Binary Load Request
sid 2014148 format suricata
et-open exploit-kit
ET EXPLOIT_KIT DRIVEBY Java Rhino Scripting Engine Exploit Downloaded
sid 2014243 format suricata
et-open exploit-kit
ET EXPLOIT_KIT DRIVEBY Java Atomic Exploit Downloaded
sid 2014295 format suricata
et-open exploit-kit
ET EXPLOIT_KIT DRIVEBY Incognito Payload Download /load/*exe
sid 2014314 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Likely Scalaxy Exploit Kit URL template download
sid 2014362 format suricata
sid 2014407 format suricata
sid 2014408 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Possible Dynamic DNS Exploit Pack Landing Page /de/sN
sid 2014446 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Possible Dynamic Dns Exploit Pack Java exploit
sid 2014447 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Exploit Kit Delivering JAR Archive to Client
sid 2014526 format suricata
et-open exploit-kit
ET EXPLOIT_KIT TDS Sutra - redirect received
sid 2014542 format suricata
et-open exploit-kit
ET EXPLOIT_KIT TDS Sutra - request in.cgi
sid 2014543 format suricata
et-open exploit-kit
ET EXPLOIT_KIT TDS Sutra - cookie set
sid 2014544 format suricata
et-open exploit-kit
ET EXPLOIT_KIT TDS Sutra - page redirecting to a SutraTDS
sid 2014545 format suricata
et-open exploit-kit
ET EXPLOIT_KIT TDS Sutra - HTTP header redirecting to a SutraTDS
sid 2014546 format suricata
et-open exploit-kit
ET EXPLOIT_KIT TDS Sutra - redirect received
sid 2014547 format suricata
et-open exploit-kit
ET EXPLOIT_KIT TDS Sutra - cookie set
sid 2014548 format suricata
et-open exploit-kit
ET EXPLOIT_KIT TDS Sutra - page redirecting to a SutraTDS
sid 2014549 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Incognito Exploit Kit Java request to images.php?t=
sid 2014609 format suricata
et-open exploit-kit
ET EXPLOIT_KIT TDS Sutra - cookie set RULEZ
sid 2014611 format suricata
et-open exploit-kit
ET EXPLOIT_KIT TDS Sutra - cookie is set RULEZ
sid 2014612 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Incognito Exploit Kit PDF request to images.php?t=81118
sid 2014639 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Unkown exploit kit pdf download
sid 2014657 format suricata
et-open exploit-kit
ET EXPLOIT_KIT DRIVEBY Generic - Redirection to Kit - BrowserDetect with var stopit
sid 2014665 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Bleeding Life 2 GPLed Exploit Pack exploit request
sid 2014705 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Bleeding Life 2 GPLed Exploit Pack payload request (exploit successful!)
sid 2014706 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Bleeding Life 2 GPLed Exploit Pack payload download
sid 2014707 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Fragus Exploit jar Download
sid 2014802 format suricata
sid 2014846 format suricata
sid 2014851 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Likely TDS redirecting to exploit kit
sid 2014854 format suricata
et-open exploit-kit
ET EXPLOIT_KIT Redirect to driveby sid=mix
sid 2014866 format suricata
et-open exploit-kit
ET EXPLOIT_KIT NuclearPack - Landing Page Received - applet archive=32CharHex
sid 2014915 format suricata
et-open exploit-kit
ET EXPLOIT_KIT DRIVEBY Incognito Payload Requested /getfile.php by Java Client
sid 2014924 format suricata
et-open exploit-kit
ET EXPLOIT_KIT - Landing Page Requested - 15Alpha1Digit.php
sid 2014967 format suricata
et-open exploit-kit
ET EXPLOIT_KIT g01pack exploit pack /mix/ payload
sid 2015011 format suricata
sid 2015478 format suricata
sid 2015573 format suricata
sid 2015574 format suricata
sid 2015593 format suricata
et-open exploit-kit
ET EXPLOIT_KIT DRIVEBY SPL - Java Exploit Requested - /spl_data/
sid 2015603 format suricata
et-open exploit-kit
ET EXPLOIT_KIT DRIVEBY SPL - Landing Page Received
sid 2015605 format suricata
Showing 1-50 of 1,915