IDS / IPS
Network IDS rules
52,690 rules · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.
◈
Rules
50 shown of 52,690
et-open
pup-activity
ET ADWARE_PUP My Search Spyware Config Download
et-open
pup-activity
ET ADWARE_PUP Freeze.com Spyware/Adware (Install)
et-open
pup-activity
ET ADWARE_PUP Freeze.com Spyware/Adware (Install Registration)
et-open
policy-violation
ET POLICY Myspace Login Attempt
et-open
trojan-activity
ET USER_AGENTS Metafisher/Goldun User-Agent (z)
et-open
web-application-attack
ET WEB_SPECIFIC_APPS PHP phpMyAgenda rootagenda Remote File Include Attempt
et-open
web-application-attack
et-open
attempted-recon
ET SCAN Potential VNC Scan 5800-5820
et-open
pup-activity
ET ADWARE_PUP Win32/Tibs Checkin
et-open
command-and-control
ET MALWARE Tibs Checkin
et-open
misc-activity
ET SCAN Rapid POP3 Connections - Possible Brute Force Attack
et-open
misc-activity
ET SCAN Rapid POP3S Connections - Possible Brute Force Attack
et-open
misc-activity
ET SCAN Rapid IMAP Connections - Possible Brute Force Attack
et-open
misc-activity
ET SCAN Rapid IMAPS Connections - Possible Brute Force Attack
et-open
policy-violation
ET POLICY Proxy Judge Discovery/Evasion (prxjdg.cgi)
et-open
non-standard-protocol
ET HUNTING Suspicious FTP 220 Banner on Local Port (-)
et-open
successful-recon-limited
ET ATTACK_RESPONSE Possible /etc/passwd via HTTP (BSD style)
et-open
policy-violation
ET GAMES STEAM Connection (v2)
et-open
successful-recon-limited
ET ATTACK_RESPONSE Possible /etc/passwd via SMTP (linux style)
et-open
successful-recon-limited
ET ATTACK_RESPONSE Possible /etc/passwd via SMTP (BSD style)
et-open
misc-activity
ET POLICY Microsoft TEREDO IPv6 tunneling
et-open
attempted-dos
ET VOIP INVITE Message Flood TCP
et-open
attempted-dos
ET VOIP REGISTER Message Flood TCP
et-open
attempted-dos
ET VOIP Multiple Unauthorized SIP Responses TCP
et-open
pup-activity
ET ADWARE_PUP Best-targeted-traffic.com Spyware Checkin
Showing 201-250 of 52,690