IDS / IPS
Network IDS rules
4,007 rules · Snort / Suricata signatures
Network intrusion-detection signatures from open rulesets (ET Open, Snort Community, abuse.ch). These match malicious traffic patterns on the wire. A rule name links to its upstream reference where the ruleset publishes one; rules without a public reference show as plain text.
◈
Rules
50 shown of 4,007
snort-community
misc-activity
MALWARE-BACKDOOR - Dagger_1.4.0
snort-community
misc-activity
MALWARE-BACKDOOR QAZ Worm Client Login access
snort-community
trojan-activity
MALWARE-BACKDOOR netbus getinfo
snort-community
trojan-activity
MALWARE-BACKDOOR NetBus Pro 2.0 connection established
snort-community
misc-activity
MALWARE-BACKDOOR Infector.1.x
snort-community
misc-activity
MALWARE-BACKDOOR Doly 2.0 access
snort-community
misc-activity
MALWARE-BACKDOOR Infector 1.6 Client to Server Connection Request
snort-community
misc-activity
MALWARE-BACKDOOR HackAttack 1.20 Connect
snort-community
suspicious-login
PROTOCOL-FTP ADMw0rm ftp login attempt
snort-community
trojan-activity
MALWARE-BACKDOOR NetSphere access
snort-community
misc-activity
MALWARE-BACKDOOR BackConstruction 2.1 Connection
snort-community
misc-activity
MALWARE-BACKDOOR BackConstruction 2.1 Client FTP Open Request
snort-community
misc-activity
MALWARE-BACKDOOR BackConstruction 2.1 Server FTP Open Reply
snort-community
misc-activity
MALWARE-BACKDOOR Matrix 2.0 Client connect
snort-community
misc-activity
MALWARE-BACKDOOR Matrix 2.0 Server access
snort-community
misc-activity
MALWARE-BACKDOOR WinCrash 1.0 Server Active
snort-community
misc-activity
MALWARE-BACKDOOR CDK
snort-community
trojan-activity
MALWARE-BACKDOOR DeepThroat 3.1 Server Response
snort-community
attempted-admin
MALWARE-BACKDOOR w00w00 attempt
snort-community
attempted-admin
MALWARE-BACKDOOR attempt
snort-community
attempted-admin
MALWARE-BACKDOOR MISC r00t attempt
snort-community
attempted-admin
MALWARE-BACKDOOR MISC rewt attempt
snort-community
attempted-admin
MALWARE-BACKDOOR MISC sm4ck attempt
snort-community
attempted-user
MALWARE-BACKDOOR MISC Solaris 2.5 attempt
snort-community
misc-activity
MALWARE-BACKDOOR HidePak backdoor attempt
snort-community
misc-activity
MALWARE-BACKDOOR HideSource backdoor attempt
snort-community
attempted-dos
PROTOCOL-ICMP TFN Probe
snort-community
attempted-dos
PROTOCOL-ICMP tfn2k icmp possible communication
snort-community
attempted-dos
MALWARE-OTHER Trin00 Daemon to Master PONG message detected
snort-community
attempted-dos
PROTOCOL-ICMP Stacheldraht server spoof
snort-community
attempted-dos
PROTOCOL-ICMP Stacheldraht gag server response
snort-community
attempted-dos
PROTOCOL-ICMP Stacheldraht server response
snort-community
attempted-dos
PROTOCOL-ICMP Stacheldraht client spoofworks
snort-community
attempted-dos
PROTOCOL-ICMP TFN client command BE
snort-community
attempted-dos
PROTOCOL-ICMP Stacheldraht client check skillz
snort-community
attempted-dos
MALWARE-OTHER Trin00 Daemon to Master message detected
snort-community
attempted-dos
PROTOCOL-ICMP Stacheldraht client check gag
Showing 1-50 of 4,007