IDS / IPS
Network IDS rules
978 rules · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.
◈
Rules
50 shown of 978
et-open
targeted-activity
et-open
targeted-activity
et-open
targeted-activity
ET MALWARE CommentCrew UGX Backdoor initial connection
et-open
targeted-activity
ET MALWARE CommentCrew downloader without user-agent string exe download without User Agent
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications get system
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications html return 1
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications sleep
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications sleep2
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications sleep3
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications sleep5
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications download client.png
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT crabdance backdoor base64 head 2
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT crabdance backdoor base64 head
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT backdoor stage 2 download base64 update.gif
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT backdoor download logo.png
et-open
targeted-activity
ET MALWARE CommentCrew Possible APT c2 communications get command client key
Showing 1-50 of 978