<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: It's possible to block custom file hash-256 in Palo alto. in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349697#M363</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14373"&gt;@claudec&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it can be helpful, if converting the hash into HEX and create a custom vulnerability to drop anything that matches the file hashes.&lt;/P&gt;&lt;P&gt;&lt;A href="https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fknowledgebase.paloaltonetworks.com%2fKCSArticleDetail%3fid%3dkA10g000000ClOFCA0&amp;amp;c=E,1,GBLRms_TacrNpkSLjQh_jBWewfsLLs39EyHbbCqSg4rCcG1FH82y1FkkUslO4-rsTLa0B6rd2Is1GKXq2LmVdS-c60Fjg_bWP5HZ5NOTfjqk1dbe828bbDI,&amp;amp;typo=1" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClOFCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I have noticed, few of&amp;nbsp;the hashes are already listed in Cisco Talos File Repute but not in PA Threat Vault.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Sep 2020 05:37:55 GMT</pubDate>
    <dc:creator>Mohammed_Yasin</dc:creator>
    <dc:date>2020-09-16T05:37:55Z</dc:date>
    <item>
      <title>It's possible to block custom file hash-256 in Palo alto.</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349114#M356</link>
      <description>&lt;DIV class="lia-message-subject lia-component-message-view-widget-subject"&gt;&lt;DIV class="MessageSubject"&gt;&lt;P&gt;It's possible to block custom file hash-256&lt;BR /&gt;It's possible to block custom file hash-256 in Palo alto.&lt;/P&gt;&lt;P&gt;Please let me know how I can check the respective file hashes disposition at a wildfire, either it is in block or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is below the file hashes need to know for disposition.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;f743c0849d69b5ea2f7eaf28831c86c1536cc27ae470f20e49223cbdba9c677c&lt;BR /&gt;e56d45628f0c2bda30ab235657704aac50a8433bdb4215c77a2e0f52f0f31a49&lt;BR /&gt;ae431797c551c20fe2f3fe1adc08a566edfabf45abbd924f0c8da06381ab6e48&lt;BR /&gt;4f7dd00a005caf046dd7e494fea25be2264974264d567edfc89122242b7c41bc&lt;BR /&gt;5ae06a8d117e876476832245039715825fbfbefc0d2463ab6c30295dd1d4afa6&lt;BR /&gt;36be48e4eac81ad77aeade20b28ff8b72275832e6833f5e1b692eb99f312fd13&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 14 Sep 2020 13:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349114#M356</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-09-14T13:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: It's possible to block custom file hash-256 in Palo alto.</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349135#M357</link>
      <description>&lt;P&gt;Unfortunately you can not create a custom threat signature based on a file hash.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At least some of the hashes you reference already have Anti-Virus signatures.&amp;nbsp; You can investigate signature availability at threatvault.paloaltonetworks.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have the actual sample you can submit it using the wildfire portal so a signature can be generated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are a Cortex XDR customer, you can black list the file hashes on your endpoints.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 14:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349135#M357</guid>
      <dc:creator>claudec</dc:creator>
      <dc:date>2020-09-14T14:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: It's possible to block custom file hash-256 in Palo alto.</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349264#M358</link>
      <description>&lt;P&gt;Thanks for your comments. Much Appreciated|||&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fknowledgebase.paloaltonetworks.com%2fKCSArticleDetail%3fid%3dkA10g000000PLOlCAO&amp;amp;c=E,1,zF-o8_KAwZpRoeWeLj8ToakCoHy1zUKQpytjHGms-mRSdFsvV85Rqodxt8L6Au2vsxw-8m2RXXjENbQZCeMnG4Z2bo6KnfZu15Xujhz7ulSM7en25mE,&amp;amp;typo=1" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLOlCAO&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I have studied and found no way to block custom files based on hash-256 only.&lt;/P&gt;&lt;P&gt;As per document file can block but based on patterns of specific file types.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case, these Hash-256 only of near firms which recently attacked by these files and damaged therefore it needs to be blocked at my end as well to avoid any risk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found few of them are blocked in wildfire but not all, so how I can add all in block state while having no file sample or pattern.&lt;/P&gt;&lt;P&gt;Please advise the way to block all these hashes-256 without a sample or pattern.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your prompt response will be highly appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 05:29:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349264#M358</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-09-15T05:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: It's possible to block custom file hash-256 in Palo alto.</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349381#M359</link>
      <description>&lt;P&gt;The only way to block a file by hash is if you have Cortex XDR on the endpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One feature that might possibly help is the new MLAV feature in PAN-OS 10.0.&amp;nbsp; Here is the information:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/wildfire-features/configure-wildfire-inline-ml.html#id45b7dbdd-c5a8-4bd9-b5a9-abf07e3ccf37" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/wildfire-features/configure-wildfire-inline-ml.html#id45b7dbdd-c5a8-4bd9-b5a9-abf07e3ccf37&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 14:45:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349381#M359</guid>
      <dc:creator>claudec</dc:creator>
      <dc:date>2020-09-15T14:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: It's possible to block custom file hash-256 in Palo alto.</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349697#M363</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14373"&gt;@claudec&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it can be helpful, if converting the hash into HEX and create a custom vulnerability to drop anything that matches the file hashes.&lt;/P&gt;&lt;P&gt;&lt;A href="https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fknowledgebase.paloaltonetworks.com%2fKCSArticleDetail%3fid%3dkA10g000000ClOFCA0&amp;amp;c=E,1,GBLRms_TacrNpkSLjQh_jBWewfsLLs39EyHbbCqSg4rCcG1FH82y1FkkUslO4-rsTLa0B6rd2Is1GKXq2LmVdS-c60Fjg_bWP5HZ5NOTfjqk1dbe828bbDI,&amp;amp;typo=1" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClOFCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I have noticed, few of&amp;nbsp;the hashes are already listed in Cisco Talos File Repute but not in PA Threat Vault.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 05:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/it-s-possible-to-block-custom-file-hash-256-in-palo-alto/m-p/349697#M363</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-09-16T05:37:55Z</dc:date>
    </item>
  </channel>
</rss>

