<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Nominated Discussion: Verdict &amp;quot;malicious&amp;quot; and action &amp;quot;allow&amp;quot; in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-verdict-quot-malicious-quot-and-action-quot/ta-p/587384</link>
    <description>&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/586478" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Verdict "malicious" and action "allow"&lt;/STRONG&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;" by &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192671"&gt;@Alpalo&lt;/a&gt;&lt;/STRONG&gt; and answered by &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/STRONG&gt; and &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Hi team&lt;/P&gt;
&lt;P&gt;We are detecting some files with&amp;nbsp;Verdict "malicious" and action "allow"&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Alpalo_0-1715594709155.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59636i0DA278BD6AB061F9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Alpalo_0-1715594709155.png" alt="Alpalo_0-1715594709155.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Can anybody help us for change the action or other solution?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WildFire log?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you click on the magnifying glass, WildFire Analysis Report tab then what does "First Seen Timestamp" show?&lt;/P&gt;
&lt;P&gt;WildFire will pass through the malicious file on first instance it sees the file and when verdict comes back from the sandbox it will show if verdict was benign or not. So in those cases you need to analyze workstation to check if it got infected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Starting from 11.0.2 there is new feature "Hold Mode for WildFire Real-Time Signature Lookup"&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/wildfire-features/hold-mode-for-wildfire-realtime-signature-lookup" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/wildfire-features/hold-mode-for-wildfire-realtime-signature-lookup&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;We have wildfire real-time configured and the action is reset-both but we are seeing that the first time the verdict is benign, one the signature is created the verdict changes to malicious but the result keeps being "allow", Is that correct? Is there any way to block this malicious files?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is expected. Please check into the feature &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/wildfire-features/hold-mode-for-wildfire-realtime-signature-lookup" target="_blank" rel="noopener"&gt;Hold Mode for WildFire Real-Time Signature Lookup.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;With this feature you can prevent the initial transfer of known malware.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="WildFire Hold Mode" style="width: 599px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59898iBA7027A5DED58BEC/image-size/large?v=v2&amp;amp;px=999" role="button" title="wildfire-hold-mode.png" alt="WildFire Hold Mode" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;WildFire Hold Mode&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 21 May 2024 14:39:54 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2024-05-21T14:39:54Z</dc:date>
    <item>
      <title>Nominated Discussion: Verdict "malicious" and action "allow"</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-verdict-quot-malicious-quot-and-action-quot/ta-p/587384</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/586478" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Verdict "malicious" and action "allow"&lt;/STRONG&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;".&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 14:39:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-verdict-quot-malicious-quot-and-action-quot/ta-p/587384</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-05-21T14:39:54Z</dc:date>
    </item>
  </channel>
</rss>

