Dropping intruders specific active connection

Question asked by Masood ahmad on Jan 8, 2018
Hi, Can someone confirm if SandBlast Threat Extraction can help dropping attacker's specific active connection? or we need to create a SAM rulebase by looking at active log connection that we want to block