<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security LifeCycle Review Flagging Unknown Binary as High Risk FileType in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/security-lifecycle-review-flagging-unknown-binary-as-high-risk/m-p/344998#M927</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/147343"&gt;@Daniyal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Beginning with the content release version 8215, Palo Alto Networks added a new file type, "unknown-binary," for customers running a PAN-OS 9.0 release. This new file type enables visibility for files that are binary encoded and not identified as any other supported file type. For customers who want visibility into transfers of "unknown-binary" files in their networks, we recommend that you set this file type to "alert" so that you can observe where these files appear in your network traffic. We also recommend that you monitor your Data Filtering logs for "Unknown Binary File" for several weeks before you consider updating to a more severe action ("block" or "continue"). If you are running a PAN-OS 9.0 release with an "alert all" rule in your file-blocking profiles (which includes the predefined "basic file blocking" and "strict file blocking" profiles), expect to see logs for "Unknown Binary File" after you install this content update; additionally, you can configure the "unknown-binary" file type in File Blocking profiles. (Customers running a PAN-OS 8.1 or earlier release will not experience any changes related to this new file type.)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Himani&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Aug 2020 15:59:43 GMT</pubDate>
    <dc:creator>hisingh</dc:creator>
    <dc:date>2020-08-21T15:59:43Z</dc:date>
    <item>
      <title>Security LifeCycle Review Flagging Unknown Binary as High Risk FileTypes</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/security-lifecycle-review-flagging-unknown-binary-as-high-risk/m-p/335801#M869</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hello All,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Can anybody in the group share their experience/Knowledge over Unknown binaries? As I am observing my Security control flagging Unknown Binaries as a High-Risk filetype. I just need to know what actually these unknown binaries are ? for what they are used for ? what are their potential threats/risk to organizations infrastructure ? and what are the possible detection and prevention methods could be deployed or used against them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been researching a lot but unable to find something convincing answers to my concerns and also want to have words from professionals here.&lt;/P&gt;&lt;P&gt;If someone ever encountered with Unknown Binaries are requested to kindly share their knowledge here.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thank you!&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 13:00:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/security-lifecycle-review-flagging-unknown-binary-as-high-risk/m-p/335801#M869</guid>
      <dc:creator>Daniyal</dc:creator>
      <dc:date>2020-06-29T13:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Security LifeCycle Review Flagging Unknown Binary as High Risk FileType</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/security-lifecycle-review-flagging-unknown-binary-as-high-risk/m-p/344998#M927</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/147343"&gt;@Daniyal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Beginning with the content release version 8215, Palo Alto Networks added a new file type, "unknown-binary," for customers running a PAN-OS 9.0 release. This new file type enables visibility for files that are binary encoded and not identified as any other supported file type. For customers who want visibility into transfers of "unknown-binary" files in their networks, we recommend that you set this file type to "alert" so that you can observe where these files appear in your network traffic. We also recommend that you monitor your Data Filtering logs for "Unknown Binary File" for several weeks before you consider updating to a more severe action ("block" or "continue"). If you are running a PAN-OS 9.0 release with an "alert all" rule in your file-blocking profiles (which includes the predefined "basic file blocking" and "strict file blocking" profiles), expect to see logs for "Unknown Binary File" after you install this content update; additionally, you can configure the "unknown-binary" file type in File Blocking profiles. (Customers running a PAN-OS 8.1 or earlier release will not experience any changes related to this new file type.)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Himani&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2020 15:59:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/security-lifecycle-review-flagging-unknown-binary-as-high-risk/m-p/344998#M927</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2020-08-21T15:59:43Z</dc:date>
    </item>
  </channel>
</rss>

