UDP flood için
alert udp $EXTERNAL_NET any -> $HOME_NET any (msg:"SLR - LOIC DoS Tool (UDP Mode) - Behavior Rule (tracking/threshold)"; threshold: type threshold, track by_src, count 100 , seconds 5; reference: url,
www.simpleweb.org/reports/loic-report.pdf
; classtype:misc-activity; sid:1234590; rev:1
TCP flood için
alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"LOIC DoS Tool v1.0.6.35 (TCP Mode) - Behavior Rule (tracking/threshold)"; flow: established,to_server; flags:S; seq:0; window:64240;threshold: type threshold, track by_src, count 400 , seconds 2; classtype:misc-attack;sid:1000006;rev:1
HTTP ping için
alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"LOIC DoS Tool v1.0.6.35 (HTTP Mode)"; flow: established,to_server; content:"|47 45 54 20 2f 20 48 54 54 50 2f 31 2e 30 0d 0a 0d 0a 0d 0a|"; threshold: type threshold, track by_src, count 400 , seconds 2;classtype:misc-attack;sid:1000005; rev:1