IDS / IPS
Network IDS rules
52,690 rules · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.
◈
Rules
50 shown of 52,690
et-open
attempted-user
ET WEB_SERVER SQL sp_password attempt
et-open
attempted-user
ET WEB_SERVER SQL sp_delete_alert attempt
et-open
misc-activity
ET POLICY Outbound Multiple Non-SMTP Server Emails
et-open
misc-activity
ET INFO IRC Nick change on non-standard port
et-open
trojan-activity
ET MALWARE IRC Private message on non-standard port
et-open
non-standard-protocol
ET POLICY IRC DCC file transfer request on non-std port
et-open
policy-violation
ET MALWARE IRC DCC chat request on non-standard port
et-open
policy-violation
ET MALWARE IRC Channel join on non-standard port
et-open
policy-violation
ET MALWARE IRC DNS request on non-standard port
et-open
misc-activity
ET CHAT IRC authorization message
et-open
string-detect
ET ATTACK_RESPONSE FTP inaccessible directory access COM1
et-open
string-detect
ET ATTACK_RESPONSE FTP inaccessible directory access COM2
et-open
string-detect
ET ATTACK_RESPONSE FTP inaccessible directory access COM3
et-open
string-detect
ET ATTACK_RESPONSE FTP inaccessible directory access COM4
et-open
string-detect
ET ATTACK_RESPONSE FTP inaccessible directory access LPT1
et-open
string-detect
ET ATTACK_RESPONSE FTP inaccessible directory access LPT2
et-open
string-detect
ET ATTACK_RESPONSE FTP inaccessible directory access LPT3
et-open
string-detect
ET ATTACK_RESPONSE FTP inaccessible directory access LPT4
et-open
string-detect
ET ATTACK_RESPONSE FTP inaccessible directory access AUX
et-open
string-detect
ET ATTACK_RESPONSE FTP inaccessible directory access NULL
et-open
misc-attack
ET EXPLOIT Pwdump3e Password Hash Retrieval port 445
et-open
misc-attack
ET EXPLOIT Pwdump3e pwservice.exe Access port 445
et-open
suspicious-login
ET EXPLOIT Pwdump3e Session Established Reg-Entry port 139
et-open
suspicious-login
ET EXPLOIT Pwdump3e Session Established Reg-Entry port 445
et-open
misc-attack
ET EXPLOIT Pwdump3e pwservice.exe Access port 139
et-open
misc-attack
ET EXPLOIT Pwdump3e Password Hash Retrieval port 139
et-open
policy-violation
ET POLICY AOL Webmail Message Send
et-open
misc-activity
ET EXPLOIT NTDump Session Established Reg-Entry port 139
et-open
misc-activity
ET EXPLOIT NTDump.exe Service Started port 139
et-open
misc-activity
Showing 1-50 of 52,690