Name
Signature ID
Information
Severity
verylow
low
medium
high
severe
Platform
All
Win95/98
WinNT
WinXP/2000
Linux
FreeBSD
Solaris
SGI
Other-Unix
Network-Device
Service
DNS
FINGER
FTP
MYSQL
ICMP
IM
IMAP
MISC
NETBIOS
NNTP
ORACLE
P2P
POP2
POP3
RPC
RSERVICES
SMTP
SNMP
SQL
TELNET
TFTP
n/a
WEB_ATTACKS
WEB_CGI
WEB_FRONTPAGE
WEB_IIS
WEB_MISC
WEB_PHP
MISC_BACKDOOR
MISC_DDOS
MISC_EXPLOIT
Policy Type
AccessControl
TrojanHorse
BufferOverflow
DDOS
IM
Other
P2P
Porn
Scan
SPAM
VirusWorm
WebAttacks
Frequency
Threshold
Packet(s)/
Second(s)
Header Options
Network Protocol
IPv4
Type of Service
Equal
Not-Equal
Identification
Fragmentation
Reserved Bit
Don't Fragment
More Fragment
Fragment Offset
Equal
Smaller
Greater
Time to Live
Equal
Smaller
Greater
IP Options
Any
End of IP List
Loose Source Routing
No IP Options
Record Route
IP Stream Identifier
IP Security Option
Strict Source Routing
Timestamp
Same IP
Transport Protocol
TCP
UDP
ICMP
Port
Source Port
Destination Port
Flow
Established
Stateless
To Client
To Server
From Client
From Server
No Stream
Only Stream
Flags
SYN
FIN
RST
PSH
ACK
URG
Reserved 1 (MSB)
Reserved 2
Sequence Number
Ack Number
Window Size
Equal
Not-Equal
Port
Source Port
Destination Port
Type
Code
ID
Sequence Number
Payload Options
Payload Size
Equal
Smaller
Greater
Byte(s)
Patterns
Offset
Relative to start of payload
Content
Case-insensitive
Decode as URI
Offset
Relative to start of payload
Relative to end of last match
Content
Case-insensitive
Within
bytes
Decode as URI
Offset
Relative to start of payload
Relative to end of last match
Content
Case-insensitive
Within
bytes
Decode as URI
Offset
Relative to start of payload
Relative to end of last match
Content
Case-insensitive
Within
bytes
Decode as URI
Offset
Relative to start of payload
Relative to end of last match
Content
Case-insensitive
Within
bytes
Decode as URI
Offset
Relative to start of payload
Relative to end of last match
Content
Case-insensitive
Within
bytes
Decode as URI
Offset
Relative to start of payload
Relative to end of last match
Content
Case-insensitive
Within
bytes
Decode as URI
Offset
Relative to start of payload
Relative to end of last match
Content
Case-insensitive
Within
bytes
Decode as URI
Offset
Relative to start of payload
Relative to end of last match
Content
Case-insensitive
Within
bytes
Decode as URI
Offset
Relative to start of payload
Relative to end of last match
Content
Case-insensitive
Within
bytes
Decode as URI