<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WildFire not Blocking File with 'malicious' Verdict in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-not-blocking-file-with-malicious-verdict/m-p/203929#M259</link>
    <description>&lt;P&gt;Hi Mivaldi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tnx for the update and that explains a lot &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Mar 2018 18:20:01 GMT</pubDate>
    <dc:creator>GOMEZZZ</dc:creator>
    <dc:date>2018-03-06T18:20:01Z</dc:date>
    <item>
      <title>WildFire not Blocking File with 'malicious' Verdict</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-not-blocking-file-with-malicious-verdict/m-p/203905#M256</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am playing in lab with wildfire and i would like to drop file downloads that are analyzed by wildfire as malicious verdict.&lt;/P&gt;&lt;P&gt;I have configured the follwong wildfire submission profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i created a wildfire profile (copy of the default)&lt;/P&gt;&lt;P&gt;admin@PA-220# show&lt;BR /&gt;wildfire {&lt;BR /&gt;rules {&lt;BR /&gt;default {&lt;BR /&gt;application any;&lt;BR /&gt;file-type any;&lt;BR /&gt;direction both;&lt;BR /&gt;analysis public-cloud;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also create an antivirus profile to have an action of reset both for wildfire.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Antivirus - WildFire" {&lt;BR /&gt;decoder {&lt;BR /&gt;http {&lt;BR /&gt;action reset-both;&lt;BR /&gt;wildfire-action reset-both;&lt;BR /&gt;}&lt;BR /&gt;smtp {&lt;BR /&gt;action default;&lt;BR /&gt;wildfire-action alert;&lt;BR /&gt;}&lt;BR /&gt;imap {&lt;BR /&gt;action default;&lt;BR /&gt;wildfire-action alert;&lt;BR /&gt;}&lt;BR /&gt;pop3 {&lt;BR /&gt;action default;&lt;BR /&gt;wildfire-action alert;&lt;BR /&gt;}&lt;BR /&gt;ftp {&lt;BR /&gt;action reset-both;&lt;BR /&gt;wildfire-action reset-both;&lt;BR /&gt;}&lt;BR /&gt;smb {&lt;BR /&gt;action default;&lt;BR /&gt;wildfire-action alert;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created a security policy with these secuirty profiles attached bot the malware test file from palo alto over http is still going through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"OUTBOUND ACCESS POLICY" {&lt;BR /&gt;to UNTRUST;&lt;BR /&gt;from TRUST;&lt;BR /&gt;source any;&lt;BR /&gt;destination any;&lt;BR /&gt;source-user any;&lt;BR /&gt;category any;&lt;BR /&gt;application any;&lt;BR /&gt;service any;&lt;BR /&gt;hip-profiles any;&lt;BR /&gt;action allow;&lt;BR /&gt;profile-setting {&lt;BR /&gt;profiles {&lt;BR /&gt;url-filtering home-filter;&lt;BR /&gt;virus "Antivirus - WildFire";&lt;BR /&gt;spyware strict;&lt;BR /&gt;vulnerability strict;&lt;BR /&gt;wildfire-analysis wildfire;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;The verdict is malicous bot the action i allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Schermafbeelding 2018-03-06 om 17.20.14.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14126i395F461253B12A24/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Schermafbeelding 2018-03-06 om 17.20.14.png" alt="Schermafbeelding 2018-03-06 om 17.20.14.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can somebody tell me what is misconfigure on my end?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Frederik.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 16:23:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-not-blocking-file-with-malicious-verdict/m-p/203905#M256</guid>
      <dc:creator>GOMEZZZ</dc:creator>
      <dc:date>2018-03-06T16:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire not Blocking File with 'malicious' Verdict</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-not-blocking-file-with-malicious-verdict/m-p/203917#M257</link>
      <description>&lt;P&gt;There are a&amp;nbsp;couple things that are incorrect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first thing is,&amp;nbsp;you are assuming that a Malicious verdict from WildFire on a file, means instantaneous Antivirus coverage. Once WildFire determines a sample is malicious, it sends it to PAN-AV, which generates a signature for the sample. This signature is then stacked, and is released every 5 minutes. You have to actually fetch the WildFire-Virus database to the firewall through Dynamic Updates for it to have the signature to detect files matching its pattern.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The second thing, is you are assuming WildFire would create an AV signature for the WildFire PE file, and that's not true. The WildFire PE file is only meant to test the WildFire forwarding (uploading sample to WildFire) and receiving back a report from WildFire, but it does not send the WildFire PE file to PAN-AV, so a signature is never generated for it.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 17:41:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-not-blocking-file-with-malicious-verdict/m-p/203917#M257</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-03-06T17:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire not Blocking File with 'malicious' Verdict</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-not-blocking-file-with-malicious-verdict/m-p/203929#M259</link>
      <description>&lt;P&gt;Hi Mivaldi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tnx for the update and that explains a lot &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 18:20:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/wildfire-not-blocking-file-with-malicious-verdict/m-p/203929#M259</guid>
      <dc:creator>GOMEZZZ</dc:creator>
      <dc:date>2018-03-06T18:20:01Z</dc:date>
    </item>
  </channel>
</rss>

