<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Signature for Email Headers in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/79024#M101</link>
    <description>&lt;P style="font: 14px/20px Lato, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; margin: 0px; padding: 0px; color: rgb(51, 51, 51); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; white-space: normal; widows: 1; font-size-adjust: none; font-stretch: normal; -webkit-text-stroke-width: 0px;"&gt;Hi clewis.&lt;/P&gt;
&lt;P style="font: 14px/20px Lato, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; margin: 0px; padding: 0px; color: rgb(51, 51, 51); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; white-space: normal; widows: 1; font-size-adjust: none; font-stretch: normal; -webkit-text-stroke-width: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font: 14px/20px Lato, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; margin: 0px; padding: 0px; color: rgb(51, 51, 51); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; white-space: normal; widows: 1; font-size-adjust: none; font-stretch: normal; -webkit-text-stroke-width: 0px;"&gt;I tested this signature in a lab with every variant of the domain you provided, and it triggered in each instance.&lt;/P&gt;
&lt;P style="font: 14px/20px Lato, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; margin: 0px; padding: 0px; color: rgb(51, 51, 51); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; white-space: normal; widows: 1; font-size-adjust: none; font-stretch: normal; -webkit-text-stroke-width: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font: 14px/20px Lato, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; margin: 0px; padding: 0px; color: rgb(51, 51, 51); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; white-space: normal; widows: 1; font-size-adjust: none; font-stretch: normal; -webkit-text-stroke-width: 0px;"&gt;Do you have a packet capture of the offending traffic?&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jun 2016 15:02:14 GMT</pubDate>
    <dc:creator>rcole</dc:creator>
    <dc:date>2016-06-02T15:02:14Z</dc:date>
    <item>
      <title>Custom Signature for Email Headers</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/78952#M94</link>
      <description>&lt;P&gt;I am trying &amp;nbsp;to create a custom signature with the purpose of preventing malicious/phishing/spam emails with the firewall before it hits our mail gateway. For the most part we have been successful with this technique but I am struggling with creating a signature to essentially work as a wildcard. If anyone could take a look at my scenario and provide any feedback it would be much appreciated. Below is my example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenairo: we are receiveing unwanted emais from the following email address&lt;/P&gt;
&lt;P&gt;scanner@abc.domain.com&lt;/P&gt;
&lt;P&gt;scanner@abcd.domain.com&lt;/P&gt;
&lt;P&gt;scanner@abcde.domain.com&lt;/P&gt;
&lt;P&gt;scanner@aaa.domain.com&lt;/P&gt;
&lt;P&gt;scanner@bbb.domain.com&lt;/P&gt;
&lt;P&gt;scanner@ccc.domain.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see the consistent parts of this type email campaign is the &lt;FONT color="#ff0000"&gt;&lt;SPAN style="line-height: normal;"&gt;scanner&lt;/SPAN&gt;&lt;/FONT&gt;@abc.&lt;FONT color="#FF0000"&gt;domain.com&lt;FONT color="#000000"&gt;. I am hoping to come up with a signature using email headers to wildcard the '&lt;/FONT&gt;abc, abcd,abcda, etc&lt;FONT color="#000000"&gt;' &amp;nbsp;as I dont want to be writing individual signatures for each sub domain as this could include upto 15 different representations of 'abc'. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;I thought this would work&amp;nbsp;&lt;FONT color="#FF0000"&gt;scanner@(.*)(\.domain\.com)&lt;/FONT&gt; but does not appear to be the case.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="pic.PNG" style="width: 472px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4245iB993DF10D0B36DAC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="pic.PNG" alt="pic.PNG" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="pic.PNG" style="width: 472px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4245iB993DF10D0B36DAC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="pic.PNG" alt="pic.PNG" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="pic.PNG" style="width: 472px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4245iB993DF10D0B36DAC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="pic.PNG" alt="pic.PNG" /&gt;&lt;/span&gt;﻿&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 17:29:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/78952#M94</guid>
      <dc:creator>clewis1</dc:creator>
      <dc:date>2016-06-01T17:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for Email Headers</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/78959#M95</link>
      <description>&lt;P&gt;Good afternoon!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would try:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;scanner@[a-z]+\.domain\.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This operates under the assumption that the child domain under domain.com consists of any number of the characters a-z.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 18:03:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/78959#M95</guid>
      <dc:creator>rcole</dc:creator>
      <dc:date>2016-06-01T18:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for Email Headers</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/79018#M99</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/28524" target="_blank"&gt;rcole&lt;/A&gt;. I will give this a shot.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 14:25:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/79018#M99</guid>
      <dc:creator>clewis1</dc:creator>
      <dc:date>2016-06-02T14:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for Email Headers</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/79023#M100</link>
      <description>&lt;P&gt;Unfortunately this signature did not work either.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 14:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/79023#M100</guid>
      <dc:creator>clewis1</dc:creator>
      <dc:date>2016-06-02T14:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for Email Headers</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/79024#M101</link>
      <description>&lt;P style="font: 14px/20px Lato, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; margin: 0px; padding: 0px; color: rgb(51, 51, 51); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; white-space: normal; widows: 1; font-size-adjust: none; font-stretch: normal; -webkit-text-stroke-width: 0px;"&gt;Hi clewis.&lt;/P&gt;
&lt;P style="font: 14px/20px Lato, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; margin: 0px; padding: 0px; color: rgb(51, 51, 51); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; white-space: normal; widows: 1; font-size-adjust: none; font-stretch: normal; -webkit-text-stroke-width: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font: 14px/20px Lato, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; margin: 0px; padding: 0px; color: rgb(51, 51, 51); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; white-space: normal; widows: 1; font-size-adjust: none; font-stretch: normal; -webkit-text-stroke-width: 0px;"&gt;I tested this signature in a lab with every variant of the domain you provided, and it triggered in each instance.&lt;/P&gt;
&lt;P style="font: 14px/20px Lato, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; margin: 0px; padding: 0px; color: rgb(51, 51, 51); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; white-space: normal; widows: 1; font-size-adjust: none; font-stretch: normal; -webkit-text-stroke-width: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font: 14px/20px Lato, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; margin: 0px; padding: 0px; color: rgb(51, 51, 51); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; white-space: normal; widows: 1; font-size-adjust: none; font-stretch: normal; -webkit-text-stroke-width: 0px;"&gt;Do you have a packet capture of the offending traffic?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 15:02:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/79024#M101</guid>
      <dc:creator>rcole</dc:creator>
      <dc:date>2016-06-02T15:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for Email Headers</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/80454#M103</link>
      <description>&lt;P&gt;I've been using this method for a while successfully...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="email-sig.PNG" style="width: 483px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4351i23DBA05CB32EC5B5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="email-sig.PNG" alt="email-sig.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2016 20:32:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/80454#M103</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2016-06-08T20:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Signature for Email Headers</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/86795#M104</link>
      <description>&lt;P&gt;I think I may be having an issue with decryption which may be casuing the issue. Just getting back around to looking at this one&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 10:56:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-email-headers/m-p/86795#M104</guid>
      <dc:creator>clewis1</dc:creator>
      <dc:date>2016-06-15T10:56:35Z</dc:date>
    </item>
  </channel>
</rss>

