Snort Rules

attempted-user

attempted-admin

rpc-portmap-decode

web-application-activity

misc-activity

misc-attack

trojan-activity

protocol-command-decode

attempted-recon

attempted-dos

policy-violation

suspicious-login

web-application-attack

bad-unknown

shellcode-detect

suspicious-filename-detect

successful-admin

successful-recon-limited

unsuccessful-user

denial-of-service

network-scan

default-login-attempt

string-detect

system-call-detect

unknown

successful-user

non-standard-protocol