<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sinkhole dns-wildfire in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/sinkhole-dns-wildfire/m-p/232176#M419</link>
    <description>&lt;P&gt;How does the dns-wildfire threat category work? I've seen a log entry, but there isn't any traffic to the sinkhole IP. The action is sinkhole and reported as generic:malicious.domain1. I have confirmed that sinkhole does work for regular threat category dns and is reported as Suspicious DNS Query (generic:malicious.domain2).&lt;/P&gt;</description>
    <pubDate>Mon, 24 Sep 2018 22:11:26 GMT</pubDate>
    <dc:creator>mike406</dc:creator>
    <dc:date>2018-09-24T22:11:26Z</dc:date>
    <item>
      <title>Sinkhole dns-wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/sinkhole-dns-wildfire/m-p/232176#M419</link>
      <description>&lt;P&gt;How does the dns-wildfire threat category work? I've seen a log entry, but there isn't any traffic to the sinkhole IP. The action is sinkhole and reported as generic:malicious.domain1. I have confirmed that sinkhole does work for regular threat category dns and is reported as Suspicious DNS Query (generic:malicious.domain2).&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 22:11:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/sinkhole-dns-wildfire/m-p/232176#M419</guid>
      <dc:creator>mike406</dc:creator>
      <dc:date>2018-09-24T22:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sinkhole dns-wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/sinkhole-dns-wildfire/m-p/233812#M423</link>
      <description>&lt;P&gt;Sinkholing a DNS query does not guarantee a followup IP connection, especially if the Spyware has embedded intelligence to distinguish a true public IP vs a dummy sinkhole IP.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 22:56:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/sinkhole-dns-wildfire/m-p/233812#M423</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-10-03T22:56:23Z</dc:date>
    </item>
  </channel>
</rss>

