Hello,
I was wondering if snort does some correlations ?
I mean something like : dont alert if the rule A has matched, but only alert if the rule A has matched and then the rule B has also matched.
Is Sophos able to do that or it does only match content for one packet?
This thread was automatically locked due to age.