<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WildFire API Malware Hashes in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-api-malware-hashes/m-p/217023#M1687</link>
    <description>&lt;P&gt;Thanks for the options.&amp;nbsp; I forgot about API and will go that route as we're still on 7.1 and not yet an AutoFocus subscriber.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jun 2018 15:45:32 GMT</pubDate>
    <dc:creator>jt1025</dc:creator>
    <dc:date>2018-06-07T15:45:32Z</dc:date>
    <item>
      <title>WildFire API Malware Hashes</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-api-malware-hashes/m-p/215779#M1682</link>
      <description>&lt;P&gt;I'm trying to get the file hash values for all submissions WildFire deems as malware.&amp;nbsp; Is this possible?&amp;nbsp; From what I've read you have to specify the hash value in the API call but I'd just like a list of all values.&lt;/P&gt;</description>
      <pubDate>Tue, 29 May 2018 20:02:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-api-malware-hashes/m-p/215779#M1682</guid>
      <dc:creator>jt1025</dc:creator>
      <dc:date>2018-05-29T20:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire API Malware Hashes</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-api-malware-hashes/m-p/216393#M1684</link>
      <description>&lt;P&gt;I don't think you can.&amp;nbsp; The idea of the API is to query for an Ad Hoc verdict not to pull the data for a separate or offline solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Jun 2018 14:00:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-api-malware-hashes/m-p/216393#M1684</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-06-02T14:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire API Malware Hashes</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-api-malware-hashes/m-p/216931#M1686</link>
      <description>&lt;P&gt;As &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas&lt;/a&gt; said, you can't do this with the WildFire API, but there are a couple other solutions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. The sha256 hashes are available on the Firewalls/Panorama.&amp;nbsp; They can output via syslog or webhook as they happen, or you can query them via the PAN-OS API.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/81/pan-os/xml-api/pan-os-xml-api-request-types/retrieve-logs-api#id9888056f-a9b3-4b36-8033-a8bd5f5ce0bd" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/81/pan-os/xml-api/pan-os-xml-api-request-types/retrieve-logs-api#id9888056f-a9b3-4b36-8033-a8bd5f5ce0bd&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. AutoFocus subscribers can get a list of hashes via the AutoFocus API.&amp;nbsp; Here's an example request for hashes of all 'private' malware samples, which means all samples submitted by your organization to WildFire:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-searches/search-samples-and-sessions" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-searches/search-samples-and-sessions&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And an example result showing the sha256, md5, and sha1 hashes of one of the samples returned:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-searches/view-search-results" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-searches/view-search-results&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 03:10:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-api-malware-hashes/m-p/216931#M1686</guid>
      <dc:creator>btorresgil</dc:creator>
      <dc:date>2018-06-07T03:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire API Malware Hashes</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-api-malware-hashes/m-p/217023#M1687</link>
      <description>&lt;P&gt;Thanks for the options.&amp;nbsp; I forgot about API and will go that route as we're still on 7.1 and not yet an AutoFocus subscriber.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/wildfire-api-malware-hashes/m-p/217023#M1687</guid>
      <dc:creator>jt1025</dc:creator>
      <dc:date>2018-06-07T15:45:32Z</dc:date>
    </item>
  </channel>
</rss>

