I have need of your aid. I must write a rule for Snort that make an alarm in the case in which a packet contains one pattern A and not contains a pattern B at the same time.
I know the "content" options, but it doesn't support the boolean and.
Thank you for yours suggest.
Igor




Reply With Quote