<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is XP Detection Signature not consistantly tripping? in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/why-is-xp-detection-signature-not-consistantly-tripping/m-p/34946#M839</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have created a custom vulnerability signature to detect XP devices based on identifying the user agent string as described in&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6948"&gt;Custom vulnerability signature for identifying Windows XP clients&lt;/A&gt; .&amp;nbsp;&amp;nbsp; The issue we are encountering is that the signature by default has an action of alert but in the vulnerability profile there is an exception response of reset-client. The issue we encountering is that the signature action is inconsistant.&amp;nbsp; We are seeing threat log entries with the action of alert as opposed to the anticipated action of reset-client.&amp;nbsp; Any ideas what might be causing this behavior?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas or thoughts would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Apr 2015 01:51:14 GMT</pubDate>
    <dc:creator>HITSSEC</dc:creator>
    <dc:date>2015-04-16T01:51:14Z</dc:date>
    <item>
      <title>Why is XP Detection Signature not consistantly tripping?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/why-is-xp-detection-signature-not-consistantly-tripping/m-p/34946#M839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have created a custom vulnerability signature to detect XP devices based on identifying the user agent string as described in&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6948"&gt;Custom vulnerability signature for identifying Windows XP clients&lt;/A&gt; .&amp;nbsp;&amp;nbsp; The issue we are encountering is that the signature by default has an action of alert but in the vulnerability profile there is an exception response of reset-client. The issue we encountering is that the signature action is inconsistant.&amp;nbsp; We are seeing threat log entries with the action of alert as opposed to the anticipated action of reset-client.&amp;nbsp; Any ideas what might be causing this behavior?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas or thoughts would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2015 01:51:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/why-is-xp-detection-signature-not-consistantly-tripping/m-p/34946#M839</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2015-04-16T01:51:14Z</dc:date>
    </item>
  </channel>
</rss>

