<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic &amp;quot;Informational&amp;quot; threat has default action of &amp;quot;drop-reset&amp;quot; in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/163685#M34</link>
    <description>&lt;P&gt;Threat 30861 "&lt;SPAN&gt;Microsoft Windows Server Service NetrServerGetInfo Opnum 21 Access Attempt" has a severity level of "Informational" but a default action of "drop-reset". &amp;nbsp;Is it common for such a low sev level threat to have such a drastic response? &amp;nbsp;It seems like all of the others that I've spot checked have had an "alert" response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It's an older threat from 2009 that was updated in May 2017, maybe something related to that?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jun 2017 19:30:27 GMT</pubDate>
    <dc:creator>craig.brooker</dc:creator>
    <dc:date>2017-06-28T19:30:27Z</dc:date>
    <item>
      <title>"Informational" threat has default action of "drop-reset"</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/163685#M34</link>
      <description>&lt;P&gt;Threat 30861 "&lt;SPAN&gt;Microsoft Windows Server Service NetrServerGetInfo Opnum 21 Access Attempt" has a severity level of "Informational" but a default action of "drop-reset". &amp;nbsp;Is it common for such a low sev level threat to have such a drastic response? &amp;nbsp;It seems like all of the others that I've spot checked have had an "alert" response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It's an older threat from 2009 that was updated in May 2017, maybe something related to that?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 19:30:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/163685#M34</guid>
      <dc:creator>craig.brooker</dc:creator>
      <dc:date>2017-06-28T19:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: "Informational" threat has default action of "drop-reset"</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/166321#M42</link>
      <description>&lt;P&gt;I just opened a case today because this was resetting the connections of our Global Protect users when they would try to access internal network shares. Seems like a false positive to me. I'm collecting info about the connections for PA Support so they can assess it further.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 14:22:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/166321#M42</guid>
      <dc:creator>bballinger</dc:creator>
      <dc:date>2017-07-13T14:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: "Informational" threat has default action of "drop-reset"</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/167161#M43</link>
      <description>&lt;P&gt;Interesting. &amp;nbsp;Did PA provide a resolution?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 13:11:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/167161#M43</guid>
      <dc:creator>craig.brooker</dc:creator>
      <dc:date>2017-07-19T13:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: "Informational" threat has default action of "drop-reset"</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/170875#M51</link>
      <description>&lt;P&gt;This is boning me as well, causing a fair amount of havok. Any word from PA on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something as simple as typing "\\servername" in the windows10 search bar to browse for shares will cause a user machine to hang for a bit and the palo alto logs a blocked threat..&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10728i8C579DC0C9156D68/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are also seeing it randomly when a user attaches a file to an email in outlook and it causes the entire app to crash.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 23:03:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/170875#M51</guid>
      <dc:creator>BrandonPrice</dc:creator>
      <dc:date>2017-08-09T23:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: "Informational" threat has default action of "drop-reset"</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/171002#M52</link>
      <description>&lt;P&gt;We ended up just changing the default action to alert for that particular "threat". Probably not the best solution, but it is what it is.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="palosetting.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10737iE9131857AF2C72DA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="palosetting.png" alt="palosetting.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 12:39:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/quot-informational-quot-threat-has-default-action-of-quot-drop/m-p/171002#M52</guid>
      <dc:creator>bballinger</dc:creator>
      <dc:date>2017-08-10T12:39:29Z</dc:date>
    </item>
  </channel>
</rss>

