<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Daily Shodan scan? in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198271#M195</link>
    <description>&lt;P&gt;External Dynamic Lists can be used in security policies regardless of directionality.&amp;nbsp; Behavior will vary depending on the type of list.&amp;nbsp; In your case you can specify and IP-based EDLs within the source column of a security policy rule.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Feb 2018 16:57:42 GMT</pubDate>
    <dc:creator>bvandivier</dc:creator>
    <dc:date>2018-02-01T16:57:42Z</dc:date>
    <item>
      <title>Daily Shodan scan?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198222#M190</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We just recently made the Shodan wall of fame and I'm now getting their scan showing up every day in my Threat log. Our action is set to reset. What do you typically do in this case? Should I ignore this and accept I will be seeing this scan every day from now on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Threat Name&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;Gh0st.Gen Command and Control Traffic&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Attacker&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;66.240.205.34&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="ShodanScan.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13594iD4E4303CC382DDA8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ShodanScan.PNG" alt="ShodanScan.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 14:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198222#M190</guid>
      <dc:creator>SethArnoff</dc:creator>
      <dc:date>2018-02-01T14:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Daily Shodan scan?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198265#M193</link>
      <description>&lt;P&gt;One suggestion would be to implement Zone Protection and/or DoS Protection to block reconnaissance activity of this nature if you have not already done so.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Understanding-DoS-Protection/ta-p/54562?attachment-id=1085" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Understanding-DoS-Protection/ta-p/54562?attachment-id=1085&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Otherwise, you could implement the use of EDLs in conjunction with an automated feed from somewhere such as Minemeld to dynamically block Shodan activity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/use-an-external-dynamic-list-in-policy/external-dynamic-list" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/use-an-external-dynamic-list-in-policy/external-dynamic-list&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Connecting-PAN-OS-to-MineMeld-using-External-Dynamic-Lists/ta-p/190414" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Connecting-PAN-OS-to-MineMeld-using-External-Dynamic-Lists/ta-p/190414&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld/ct-p/MineMeld" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld/ct-p/MineMeld&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 16:30:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198265#M193</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-02-01T16:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Daily Shodan scan?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198269#M194</link>
      <description>&lt;P&gt;Thank you! The Zone Protection was what I was looking for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question on EDL: I have it setup to block Outgoing IP's, but this Shodan scan is Incoming. I'm assuming I can set an EDL to also block Incoming connections by setting the EDL in the Source Address as opposed to Destination?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 16:46:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198269#M194</guid>
      <dc:creator>SethArnoff</dc:creator>
      <dc:date>2018-02-01T16:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Daily Shodan scan?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198271#M195</link>
      <description>&lt;P&gt;External Dynamic Lists can be used in security policies regardless of directionality.&amp;nbsp; Behavior will vary depending on the type of list.&amp;nbsp; In your case you can specify and IP-based EDLs within the source column of a security policy rule.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 16:57:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198271#M195</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-02-01T16:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Daily Shodan scan?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198286#M198</link>
      <description>&lt;P&gt;Thank you again!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 17:25:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198286#M198</guid>
      <dc:creator>SethArnoff</dc:creator>
      <dc:date>2018-02-01T17:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Daily Shodan scan?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198287#M199</link>
      <description>&lt;P&gt;You are very welcome.&amp;nbsp; It was my pleasure.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 17:26:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/daily-shodan-scan/m-p/198287#M199</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-02-01T17:26:53Z</dc:date>
    </item>
  </channel>
</rss>

