<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex-XDR  hash verdict in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/331282#M165</link>
    <description>&lt;P&gt;wildfire only showing the result of files were forwarded from our security devices.its not showing the global database over there.&lt;/P&gt;&lt;P&gt;for eg:&amp;nbsp;7e27e33ec3df0ea9e89d32b050f1f0a211e3764818b9cad19308b8c954a02f03&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jun 2020 05:58:59 GMT</pubDate>
    <dc:creator>Marsooq_A</dc:creator>
    <dc:date>2020-06-03T05:58:59Z</dc:date>
    <item>
      <title>Cortex-XDR  hash verdict</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/330411#M155</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our cyber security department has shared few hashes and asked to check the these hashes verdict? How to check a hash is malware or benign? how to perform this on cortex xdr portal?&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 20:37:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/330411#M155</guid>
      <dc:creator>Marsooq_A</dc:creator>
      <dc:date>2020-05-28T20:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex-XDR  hash verdict</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/331251#M160</link>
      <description>&lt;P&gt;Your best bet is to use the WildFire portal to do a hash lookup.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://wildfire.paloaltonetworks.com/wildfire/reportlist/Manual" target="_blank"&gt;https://wildfire.paloaltonetworks.com/wildfire/reportlist/Manual&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep in mind, this only shows results for files known by WildFire.&amp;nbsp; If it is as unknown file, Local Analysis can still provide a verdict.&amp;nbsp; The only downside is, there is no way to know what scoring Local Analysis will give a file until the agent has a chance to see the actual file.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 04:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/331251#M160</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-06-03T04:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex-XDR  hash verdict</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/331282#M165</link>
      <description>&lt;P&gt;wildfire only showing the result of files were forwarded from our security devices.its not showing the global database over there.&lt;/P&gt;&lt;P&gt;for eg:&amp;nbsp;7e27e33ec3df0ea9e89d32b050f1f0a211e3764818b9cad19308b8c954a02f03&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 05:58:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/331282#M165</guid>
      <dc:creator>Marsooq_A</dc:creator>
      <dc:date>2020-06-03T05:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex-XDR  hash verdict</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/331286#M166</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vt.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25985i69D1D20E5DA3B9C8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vt.jpg" alt="vt.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wf.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25984i93F273D8BDC1AFF7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="wf.jpg" alt="wf.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 05:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/331286#M166</guid>
      <dc:creator>Marsooq_A</dc:creator>
      <dc:date>2020-06-03T05:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex-XDR  hash verdict</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/332169#M175</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/141755"&gt;@Marsooq_A&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can check the coverage of the hashes from threatvault.paloaltonetworks.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the hashes show up as malicious in VT and other trusted resources, do go ahead and blacklist the files.&lt;/P&gt;&lt;P&gt;If you raise a case for hash coverage check, the sample/file will be asked of you by the team; for the hashes which don't show up in wildfire db or threatvault.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 12:42:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-hash-verdict/m-p/332169#M175</guid>
      <dc:creator>LokeshKumar</dc:creator>
      <dc:date>2020-06-07T12:42:28Z</dc:date>
    </item>
  </channel>
</rss>

