IDS / IPS
Network IDS rules
10,907 rules · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.
◈
Rules
50 shown of 10,907
et-open
trojan-activity
ET MALWARE IRC Private message on non-standard port
et-open
trojan-activity
ET ATTACK_RESPONSE Zone-H.org defacement notification
et-open
trojan-activity
ET USER_AGENTS Suspicious User Agent (agent)
et-open
trojan-activity
ET MALWARE IRC Channel topic scan/exploit command
et-open
trojan-activity
ET MALWARE IRC Potential bot scan/exploit command
et-open
trojan-activity
ET MALWARE IRC potential reptile commands
et-open
trojan-activity
ET MALWARE IRC potential bot commands
et-open
trojan-activity
ET MALWARE IRC channel topic misc bot commands
et-open
trojan-activity
ET USER_AGENTS Suspicious User Agent (Microsoft Internet Explorer)
et-open
trojan-activity
ET ATTACK_RESPONSE Hostile FTP Server Banner (StnyFtpd)
et-open
trojan-activity
ET ATTACK_RESPONSE Hostile FTP Server Banner (Reptile)
et-open
trojan-activity
ET ATTACK_RESPONSE Hostile FTP Server Banner (Bot Server)
et-open
trojan-activity
ET USER_AGENTS Metafisher/Goldun User-Agent (z)
et-open
trojan-activity
ET USER_AGENTS Suspicious User-Agent - Possible Trojan Downloader (ver18/ver19 etc)
et-open
trojan-activity
ET MALWARE Downloader-5265/Torpig/Anserin/Sinowal Unique UA (MSID)
et-open
trojan-activity
ET MALWARE W32.Virut.A joining an IRC Channel
et-open
trojan-activity
ET USER_AGENTS Suspicious User-Agent outbound (bot)
et-open
trojan-activity
ET MALWARE Suspicious User Agent Detected (RookIE) - Common with Downloaders
et-open
trojan-activity
ET MALWARE Generic.Malware.SFL User-Agent (Rescue/9.11)
et-open
trojan-activity
ET MALWARE Backdoor.Irc.MFV User Agent Detected (IRC-U)
et-open
trojan-activity
ET USER_AGENTS Suspicious User-Agent (MSIE)
et-open
trojan-activity
ET USER_AGENTS Suspicious User-Agent (HTTPTEST) - Seen used by downloaders
et-open
trojan-activity
ET MALWARE Banload User-Agent Detected (ExampleDL)
et-open
trojan-activity
ET USER_AGENTS Suspicious User-Agent (MyAgent)
et-open
trojan-activity
ET USER_AGENTS Dialer-967 User-Agent
et-open
trojan-activity
ET USER_AGENTS Suspicious User-Agent (MYURL)
et-open
trojan-activity
ET P2P BearShare P2P Gnutella Client User-Agent (BearShare 6.x.x.x)
et-open
trojan-activity
ET P2P Bittorrent P2P Client User-Agent (Bittorrent/5.x.x)
et-open
trojan-activity
ET P2P Bittorrent P2P Client HTTP Request
et-open
trojan-activity
ET P2P BearShare P2P Gnutella Client HTTP Request
et-open
trojan-activity
ET USER_AGENTS Downloader User-Agent Detected (Windows Updates Manager|3.12|...)
et-open
trojan-activity
ET MALWARE Poebot Related User Agent (SPM_ID=)
Showing 1-50 of 10,907