<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Threat ID 54532 in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/threat-id-54532/m-p/524264#M681</link>
    <description>&lt;P&gt;Anyone have any experience dealing with Threat ID 54532? VBScript Obfuscation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See the offenses/detections but find nothing on the hosts source or destination that reflects a vbs script. Its all internal traffic.&amp;nbsp; Could it be some other traffic that is getting incorrectly labeled as VBS?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Dec 2022 19:20:53 GMT</pubDate>
    <dc:creator>James123456</dc:creator>
    <dc:date>2022-12-15T19:20:53Z</dc:date>
    <item>
      <title>Threat ID 54532</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/threat-id-54532/m-p/524264#M681</link>
      <description>&lt;P&gt;Anyone have any experience dealing with Threat ID 54532? VBScript Obfuscation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See the offenses/detections but find nothing on the hosts source or destination that reflects a vbs script. Its all internal traffic.&amp;nbsp; Could it be some other traffic that is getting incorrectly labeled as VBS?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 19:20:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/threat-id-54532/m-p/524264#M681</guid>
      <dc:creator>James123456</dc:creator>
      <dc:date>2022-12-15T19:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID 54532</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/threat-id-54532/m-p/524891#M697</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Yes it can be other traffic as the signatures are looking for specific items in the traffic. Best way to find out would be to create a packet capture and open a support case for the support team to review it. This is because we do not have insight into the threat definitions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 20:20:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/threat-id-54532/m-p/524891#M697</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-12-22T20:20:12Z</dc:date>
    </item>
  </channel>
</rss>

