Ross ROSS = Recommend OSS · open-source software intelligence for agents

al0ne/suricata-rules resource

Suricata IDS rules 用来检测红队渗透/恶意行为等,支持检测CobaltStrike/MSF/Empire/DNS隧道/Weevely/菜刀/冰蝎/挖矿/反弹shell/ICMP隧道等 observed · 2026-08-28

github.com/al0ne/suricata-rules observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2911
  • days_rel: n/a
  • days_push: 1152
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1283 stars · 306 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A curated collection of high-quality Suricata IDS rules for detecting red-team tooling and malicious network behavior, including CobaltStrike, Metasploit, Empire, DNS/ICMP tunneling, webshells, cryptomining, and reverse shells. Each rule is organized by threat type with accompanying pcap samples for testing and validation.

Use cases

  • detect cobalt strike beacon traffic with suricata
  • ids rules for dns tunneling detection
  • suricata signatures for webshell activity
  • alert on reverse shell connections
  • detect cryptomining traffic on the network
  • find metasploit and empire c2 traffic
  • network detection for red team tools

When to choose

  • you run Suricata and want community-vetted signatures for common attacker tools
  • you need pcap-backed rules you can test against real malicious traffic samples
  • you want a single consolidated rules file covering C2, tunneling, webshells, and mining

When to avoid

  • you use Snort rather than Suricata without adaptation
  • you need continuously updated commercial-grade threat intel feeds
  • you need host-based or endpoint detection rather than network signatures

Facets

dataset · maturity maintenance

security monitoring alerting security penetration-testing networking self-hosted ids suricata intrusion-detection network-signatures threat-detection red-team cobaltstrike dns-tunneling webshell reverse-shell linux web-server

1 source

Member repositories

RepositoryRoleHealth v2
al0ne/suricata-rulesmain32

For agents

markdown · JSON · MCP: product_card(name="al0ne/suricata-rules")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem