<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Advice on blocking the 'EXTENSION PACKS for Oracle Virtual Box in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/advice-on-blocking-the-extension-packs-for-oracle-virtual-box/m-p/522116#M451</link>
    <description>&lt;P&gt;Better consider trying DLP and the file name or even better Palo Alto XDR or another EDR solution and uploading the file hash so that it is blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-files/manage-file-execution" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-files/manage-file-execution&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=Wt6y1jcREcI" target="_blank"&gt;https://www.youtube.com/watch?v=Wt6y1jcREcI&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/search-file-and-destroy" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/search-file-and-destroy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also see this discussion:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/custom-signatures/cortex-xdr-block-file-execution-based-on-ico-file-name/td-p/441544" target="_blank"&gt;https://live.paloaltonetworks.com/t5/custom-signatures/cortex-xdr-block-file-execution-based-on-ico-file-name/td-p/441544&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2022 18:57:30 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2022-11-22T18:57:30Z</dc:date>
    <item>
      <title>Advice on blocking the 'EXTENSION PACKS for Oracle Virtual Box</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/advice-on-blocking-the-extension-packs-for-oracle-virtual-box/m-p/512877#M438</link>
      <description>&lt;P&gt;Oracle's Virtual Box is free and available to use under the GPL v2 license terms.&lt;/P&gt;
&lt;P&gt;They have Extension Pack which is not free and can invoke a software audit if found.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are looking to see if anyone has an application snippet to prevent download of the Extension Pack.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately the download is a typical download in that it is available from multiple sources&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 16:20:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/advice-on-blocking-the-extension-packs-for-oracle-virtual-box/m-p/512877#M438</guid>
      <dc:creator>Rick_Miller</dc:creator>
      <dc:date>2022-08-24T16:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Advice on blocking the 'EXTENSION PACKS for Oracle Virtual Box</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/advice-on-blocking-the-extension-packs-for-oracle-virtual-box/m-p/522116#M451</link>
      <description>&lt;P&gt;Better consider trying DLP and the file name or even better Palo Alto XDR or another EDR solution and uploading the file hash so that it is blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-files/manage-file-execution" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-files/manage-file-execution&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=Wt6y1jcREcI" target="_blank"&gt;https://www.youtube.com/watch?v=Wt6y1jcREcI&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/search-file-and-destroy" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/search-file-and-destroy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also see this discussion:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/custom-signatures/cortex-xdr-block-file-execution-based-on-ico-file-name/td-p/441544" target="_blank"&gt;https://live.paloaltonetworks.com/t5/custom-signatures/cortex-xdr-block-file-execution-based-on-ico-file-name/td-p/441544&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 18:57:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/advice-on-blocking-the-extension-packs-for-oracle-virtual-box/m-p/522116#M451</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-11-22T18:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Advice on blocking the 'EXTENSION PACKS for Oracle Virtual Box</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/advice-on-blocking-the-extension-packs-for-oracle-virtual-box/m-p/526240#M454</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/152912"&gt;@Rick_Miller&lt;/a&gt; , Did you manage to find a solution to this issue?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 17:39:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/advice-on-blocking-the-extension-packs-for-oracle-virtual-box/m-p/526240#M454</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-01-07T17:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Advice on blocking the 'EXTENSION PACKS for Oracle Virtual Box</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/advice-on-blocking-the-extension-packs-for-oracle-virtual-box/m-p/530017#M457</link>
      <description>&lt;P&gt;continue to ask for an application code like what was provided for malwarbytes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2023 19:33:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/advice-on-blocking-the-extension-packs-for-oracle-virtual-box/m-p/530017#M457</guid>
      <dc:creator>Rick_Miller</dc:creator>
      <dc:date>2023-02-06T19:33:10Z</dc:date>
    </item>
  </channel>
</rss>

