<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic THREAT false positives on MS software when using Global Protect. in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-false-positives-on-ms-software-when-using-global-protect/m-p/239717#M462</link>
    <description>&lt;P&gt;I'm seeing what look slike a lot of false positives when using global protect. For example, Microsoft's Logon.exe excutable and any MS Endpoint patches&lt;/P&gt;&lt;P&gt;An example is&lt;/P&gt;&lt;P&gt;AM_Engine_Patch_1.1.15400.4.exe&lt;BR /&gt;SHA-256 Hash: 74f9dc35fc9f5ab02e46843e8ccf569478961ea58dc2655690516199c1eab928&lt;/P&gt;&lt;P&gt;which PAN-OS 8.0.7 is flagging as Virus/Win32.WGeneric.tphtk(214705593)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't spot anything in release notes for 8.0.7+ that&lt;/P&gt;</description>
    <pubDate>Tue, 13 Nov 2018 17:44:48 GMT</pubDate>
    <dc:creator>NormCook</dc:creator>
    <dc:date>2018-11-13T17:44:48Z</dc:date>
    <item>
      <title>THREAT false positives on MS software when using Global Protect.</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-false-positives-on-ms-software-when-using-global-protect/m-p/239717#M462</link>
      <description>&lt;P&gt;I'm seeing what look slike a lot of false positives when using global protect. For example, Microsoft's Logon.exe excutable and any MS Endpoint patches&lt;/P&gt;&lt;P&gt;An example is&lt;/P&gt;&lt;P&gt;AM_Engine_Patch_1.1.15400.4.exe&lt;BR /&gt;SHA-256 Hash: 74f9dc35fc9f5ab02e46843e8ccf569478961ea58dc2655690516199c1eab928&lt;/P&gt;&lt;P&gt;which PAN-OS 8.0.7 is flagging as Virus/Win32.WGeneric.tphtk(214705593)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't spot anything in release notes for 8.0.7+ that&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 17:44:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-false-positives-on-ms-software-when-using-global-protect/m-p/239717#M462</guid>
      <dc:creator>NormCook</dc:creator>
      <dc:date>2018-11-13T17:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: THREAT false positives on MS software when using Global Protect.</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-false-positives-on-ms-software-when-using-global-protect/m-p/239741#M463</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We occasionally also see this type of behavior. Its just how the PAN see's the files and it creates a false positive. The best thing to do is create a support ticket so they can get more info and correct the signatures.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 22:43:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/threat-false-positives-on-ms-software-when-using-global-protect/m-p/239741#M463</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-11-13T22:43:31Z</dc:date>
    </item>
  </channel>
</rss>

