is there any mean to specify in wich order the rules
are applied to the traffic ?

for learning purposes, we set up a server with
snort(all rules) running on.
but when we test it with some fake attacks(with
sneeze), the rules matched are not thoose we were

pop2 exploit triggers nmap scan

