<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tofsee TLS Fingerprint Detection in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295364#M665</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Since the moment we updated our threat database to 8204-5736 we see THOUSANDS of 'Tofsee TLS Fingerprint Detection' threat matches.&lt;/P&gt;&lt;P&gt;I assume they are false positives? Anyone else seeing the same?&lt;/P&gt;&lt;P&gt;It's skewing our monitoring stats significantly so I may need to create an exception.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Oct 2019 09:08:17 GMT</pubDate>
    <dc:creator>Stephen_Elliott</dc:creator>
    <dc:date>2019-10-31T09:08:17Z</dc:date>
    <item>
      <title>Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295364#M665</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Since the moment we updated our threat database to 8204-5736 we see THOUSANDS of 'Tofsee TLS Fingerprint Detection' threat matches.&lt;/P&gt;&lt;P&gt;I assume they are false positives? Anyone else seeing the same?&lt;/P&gt;&lt;P&gt;It's skewing our monitoring stats significantly so I may need to create an exception.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 09:08:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295364#M665</guid>
      <dc:creator>Stephen_Elliott</dc:creator>
      <dc:date>2019-10-31T09:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295623#M670</link>
      <description>&lt;P&gt;Confirmed we had the same threat database yesterday (now updated). We have seen this, starting yesterday 01:00 GMT for TLS from one particular Windows 7 host, which we have shut down as a precaution. However all indications around this host's traffic point towards this being a false positive, with perhaps TLS from Windows 7 being a trigger. Since the trigger host is currently disabled, I'm unable to confirm if this is resolved in updated threat databases so would appreciate if anyone hears that this was indeed false positive and is resolved.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 11:21:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295623#M670</guid>
      <dc:creator>fatoldhippy</dc:creator>
      <dc:date>2019-11-01T11:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295659#M671</link>
      <description>&lt;P&gt;We're still seeing thousands of alerts per hour from thousands of source IPs. I can't believe that these are all real alerts.&lt;/P&gt;&lt;P&gt;There's also something odd when filtering on the threat name in the ACC - it displays no data despite the thousands of alerts displayed in the threat log and threat monitor.&lt;/P&gt;&lt;P&gt;I'll raise a TAC case and post the result here.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 13:12:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295659#M671</guid>
      <dc:creator>Stephen_Elliott</dc:creator>
      <dc:date>2019-11-01T13:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295665#M672</link>
      <description>&lt;P&gt;We have also seen this signature on most of our deployed&lt;SPAN&gt;&amp;nbsp;firewalls. Most traffic triggering this signature looks legitimate, as it is only to specific websites such as an online backup provider. I opened a case with Palo support, only to be told that these signatures "are looking for hash in the client hello packet of the SSL/TLS negotiation" but they could not be more descriptive as this is "proprietary information". It astounds me that they release 16 TLS fingerprint signatures with no documentation or references on how the firewall is cherry-picking traffic that matches this signature. I tried to inquire if they leverage JA3 fingerprints but the Palo rep stated the firewall does not hash anything so it does not.. Would love some insight into these signatures as there are 4 new Tofsee threat ID's with no details on how they are different, leaving us in the dark.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;85452&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Tofsee TLS Fingerprint Detection&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;alert&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;8.1.0&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;85453&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Tofsee TLS Fingerprint Detection&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;alert&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;8.1.0&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;85454&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Tofsee TLS Fingerprint Detection&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;alert&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;8.1.0&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;85455&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Tofsee TLS Fingerprint Detection&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;alert&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;8.1.0&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 01 Nov 2019 13:53:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295665#M672</guid>
      <dc:creator>LRichman</dc:creator>
      <dc:date>2019-11-01T13:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295668#M673</link>
      <description>&lt;P&gt;Exactly that LRichman!&lt;/P&gt;&lt;P&gt;Doesn't seem much point in me opening a case too then.&lt;/P&gt;&lt;P&gt;I'll leave a few days to see if the threat DB gets updated. If not I think I'll create an exception for these threats.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 14:08:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295668#M673</guid>
      <dc:creator>Stephen_Elliott</dc:creator>
      <dc:date>2019-11-01T14:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295689#M674</link>
      <description>&lt;P&gt;I've also open a support case yesterday. Sadly the suggestion thus far is to create an exception. I'm holding out for now because as you've all stated this seems like an adjustment they need to make on their end. We are avg right around 55-60K of these alerts popping off every hour, it's making our SIEM think the world is ending. Considering I'm seeing traffic to domains like msn.com, google.com, amazon.com, twitter.com, webex.com, yahoo.com, bing.com. I would say the fix should likely be on a much tighter signature than what they release on 10/30. The description for ID 85454 which is what is kicking them off is "This signature detects encrypted command and control traffic from Tofsee malware." I highly doubt all those domains are partaking in a C2 scenario. I too will post what support comes up with, they did say I wasn't alone and others also have complained.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 15:26:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295689#M674</guid>
      <dc:creator>AdamGajewski</dc:creator>
      <dc:date>2019-11-01T15:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295715#M675</link>
      <description>&lt;P&gt;Just heard from support who received word from engineering that they will be disabling several of the problem signatures in the next content release around Tuesday of next week. They suggested doing an exception of they are causing issues in the meantime.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 17:32:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/295715#M675</guid>
      <dc:creator>AdamGajewski</dc:creator>
      <dc:date>2019-11-01T17:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296230#M677</link>
      <description>&lt;P&gt;Same here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will keep an eye on this thread to confirm signature update resolved the mountain of Tofsee informational alerts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Stephen.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 22:52:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296230#M677</guid>
      <dc:creator>KMcKenna</dc:creator>
      <dc:date>2019-11-04T22:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296403#M678</link>
      <description>As of Threat Version 8206-5743 (10/31/19) we are still seeing the issue. This seems to be the latest version, is there another version available?</description>
      <pubDate>Tue, 05 Nov 2019 19:11:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296403#M678</guid>
      <dc:creator>rgreens</dc:creator>
      <dc:date>2019-11-05T19:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296405#M679</link>
      <description>&lt;P&gt;There does not appear to be a new version released at this time, this is the most recent version according to my firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 19:44:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296405#M679</guid>
      <dc:creator>LRichman</dc:creator>
      <dc:date>2019-11-05T19:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296621#M680</link>
      <description>&lt;P&gt;8207-5750 was released early this morning.&lt;/P&gt;&lt;P&gt;Our dynamic update schedule will install it tonight and I'll post an update here tomorrow.&lt;/P&gt;&lt;P&gt;It's available to try now though if you like.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 08:38:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296621#M680</guid>
      <dc:creator>Stephen_Elliott</dc:creator>
      <dc:date>2019-11-06T08:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296622#M681</link>
      <description>&lt;P&gt;The associated info with 8207 shows 4 'tofsee' signatures being disabled, so hopefully that should fix it!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 08:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296622#M681</guid>
      <dc:creator>Stephen_Elliott</dc:creator>
      <dc:date>2019-11-06T08:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296680#M682</link>
      <description>&lt;P&gt;They did say "around" Tuesday, though they did sneak it on last night.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our FWs downloaded and installed the latest content update (Version 8207) lat night and it resolved the issue for us.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 13:16:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296680#M682</guid>
      <dc:creator>AdamGajewski</dc:creator>
      <dc:date>2019-11-06T13:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296691#M683</link>
      <description>&lt;P&gt;I can confirm that the new content release 8207 has corrected this issue after disabling the signatures. Threat logs are looking a lot cleaner without 5k alerts an hour being flagged for those signatures.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 14:00:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296691#M683</guid>
      <dc:creator>LRichman</dc:creator>
      <dc:date>2019-11-06T14:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296704#M684</link>
      <description>&lt;P&gt;RE:Stephen 8207_5750&lt;BR /&gt;&lt;BR /&gt;We installed 8207_5750 last night at 19:00 MST and we still saw a lot after that.&amp;nbsp; Funny thing is we have this spyware rule set to grab the first packet and there isnt even a http get in it.&amp;nbsp; This has to be an over-tweaked spyware rule that PAN needs to fix.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tofsee_first_packet.jpg" style="width: 644px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22143i2F352678011E7554/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="tofsee_first_packet.jpg" alt="tofsee_first_packet.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 15:30:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296704#M684</guid>
      <dc:creator>itsnotthenetwork</dc:creator>
      <dc:date>2019-11-06T15:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296747#M686</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56004"&gt;@itsnotthenetwork&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;For us, 8207_5750 was RELEASED at 20:53:04 EST and since we are set to update around midnight we still saw the Tofsee threat signatures occur until after the signature database was updated. This may have been what you saw? I agree though the signatures were too noisy to be released in the state they are in. But now that the Tofsee signature is gone, this content update released a nice new informational signature for "Non-RFC Compliant SSL Traffic on Port 443" that has begun acting up. Thus the circle of signature life continues..&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 16:38:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296747#M686</guid>
      <dc:creator>LRichman</dc:creator>
      <dc:date>2019-11-06T16:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296755#M687</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/122067"&gt;@LRichman&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is that ( subtype eq spyware ) for the&amp;nbsp;&lt;SPAN&gt;"Non-RFC Compliant SSL Traffic on Port 443"?&amp;nbsp; Whats the signature ID for that?&lt;BR /&gt;&lt;BR /&gt;I'm not seeing any hits for&amp;nbsp;Non-RFC Compliant SSL Traffic on Port 443, but I would need to know what PAN is looking for for both signatures before I could determine why.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 16:56:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296755#M687</guid>
      <dc:creator>itsnotthenetwork</dc:creator>
      <dc:date>2019-11-06T16:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296756#M688</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56004"&gt;@itsnotthenetwork&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="x-grid3-row  x-grid3-row-over"&gt;Threat Name: Non-RFC Compliant SSL Traffic on Port 443&lt;/DIV&gt;&lt;DIV class="x-grid3-row  x-grid3-row-over"&gt;category-of-threatid eq protocol-anomaly&lt;BR /&gt;Threat ID: 56112&lt;/DIV&gt;&lt;DIV class="x-grid3-row  x-grid3-row-over"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="x-grid3-row  x-grid3-row-over"&gt;I am also not saying right off the bat that this signature is having issues, as it's only a handful of firewalls that I've seen so far and for a specific destination subnet. Could be an old website or server that is negotiating weak ciphers and the vulnerability signature is reporting a true positive. Further investigation is required before I can truly say if this is a weak signature or not&lt;/DIV&gt;</description>
      <pubDate>Wed, 06 Nov 2019 17:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296756#M688</guid>
      <dc:creator>LRichman</dc:creator>
      <dc:date>2019-11-06T17:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296977#M689</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Just to confirm that our threat monitor has stopped logging the 30k+ alerts per hour for the Tofsee detection since the db update to 8207.&lt;/P&gt;&lt;P&gt;And I'm not seeing any problems with threat id 56112 as reported by LRichman (yet!)&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 09:31:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/296977#M689</guid>
      <dc:creator>Stephen_Elliott</dc:creator>
      <dc:date>2019-11-07T09:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Tofsee TLS Fingerprint Detection</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/297061#M690</link>
      <description>&lt;P&gt;The Tofsee storm has stopped for us as well.&amp;nbsp; The weird thing was the updated applied and it appeared to take 2 hours for the threats to stop flagging, and thats on 7050 hardware.&amp;nbsp; I'm just glad its over.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 16:31:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/tofsee-tls-fingerprint-detection/m-p/297061#M690</guid>
      <dc:creator>itsnotthenetwork</dc:creator>
      <dc:date>2019-11-07T16:31:10Z</dc:date>
    </item>
  </channel>
</rss>

