Home/Network IDS rules
IDS / IPS

Network IDS rules

52,690 rules · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.

Rules

50 shown of 52,690
et-open pup-activity
ET ADWARE_PUP Best-targeted-traffic.com Spyware Install
sid 2003210 format suricata T1005 ↗
sid 2003224 format suricata
et-open command-and-control
ET MALWARE W32.Downloader Tibs.jy Reporting to C&C (2)
sid 2003239 format suricata
et-open pup-activity
ET ADWARE_PUP User-Agent (Download Agent) Possibly Related to TrinityAcquisitions.com
sid 2003243 format suricata
sid 2003254 format suricata
sid 2003255 format suricata
sid 2003256 format suricata
sid 2003257 format suricata
sid 2003258 format suricata
et-open protocol-command-decode
sid 2003259 format suricata
sid 2003260 format suricata
sid 2003261 format suricata
sid 2003262 format suricata
sid 2003263 format suricata
sid 2003266 format suricata
sid 2003267 format suricata
sid 2003268 format suricata
sid 2003269 format suricata
sid 2003270 format suricata
sid 2003271 format suricata
sid 2003272 format suricata
sid 2003273 format suricata
sid 2003274 format suricata
sid 2003275 format suricata
sid 2003276 format suricata
sid 2003277 format suricata
sid 2003278 format suricata
sid 2003279 format suricata
sid 2003280 format suricata
sid 2003281 format suricata
sid 2003306 format suricata
et-open policy-violation
sid 2003311 format suricata
et-open policy-violation
sid 2003312 format suricata
sid 2003319 format suricata
et-open attempted-admin
ET WEB_CLIENT Apple Quicktime RTSP Overflow (1)
sid 2003326 format suricata
et-open attempted-admin
ET WEB_CLIENT Apple Quicktime RTSP Overflow (2)
sid 2003327 format suricata
et-open pup-activity
ET USER_AGENTS Suspicious User Agent (Autoupdate)
sid 2003337 format suricata
et-open pup-activity
ET ADWARE_PUP Trinityacquisitions.com and Maximumexperience.com Spyware Activity
sid 2003344 format suricata
et-open pup-activity
ET ADWARE_PUP Errorsafe.com Fake antispyware User-Agent (ErrorSafe)
sid 2003346 format suricata
et-open pup-activity
ET ADWARE_PUP Gamehouse.com User-Agent (GAMEHOUSE.NET.URL)
sid 2003347 format suricata
et-open pup-activity
ET ADWARE_PUP MyGlobalSearch Spyware bar update
sid 2003351 format suricata
et-open pup-activity
ET ADWARE_PUP MyGlobalSearch Spyware bar update 2
sid 2003352 format suricata
et-open pup-activity
ET ADWARE_PUP Yourscreen.com Spyware User-Agent (FreezeInet)
sid 2003355 format suricata
et-open pup-activity
ET ADWARE_PUP Freeze.com Spyware Download
sid 2003356 format suricata
et-open trojan-activity
ET USER_AGENTS Suspicious User-Agent - Possible Trojan Downloader (ver18/ver19 etc)
sid 2003380 format suricata
et-open pup-activity
ET ADWARE_PUP Hotbar Tools Spyware User-Agent (hbtools)
sid 2003383 format suricata
et-open pup-activity
ET ADWARE_PUP SpamBlockerUtility Fake Anti-Spyware User-Agent (SpamBlockerUtility x.x.x)
sid 2003384 format suricata
sid 2003387 format suricata
sid 2003390 format suricata
et-open pup-activity
ET ADWARE_PUP Mysearch.com/Morpheus Bar Spyware User-Agent (Morpheus)
sid 2003396 format suricata
Showing 251-300 of 52,690