<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo EDL list - some malicious IPs not included in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/palo-edl-list-some-malicious-ips-not-included/m-p/1226074#M2990</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just want to make sure I understand Palo's EDL's correctly: a client has a query about 3 IP addresses that are not included in Palo's EDL, but is picked up as malicious via Virus Total and MXToolbox&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;138.199.15.177&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;179.43.149.114&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;45.148.10.237&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The client wants to know why these specific IPs are not present in the EDLs and want's Palo to investigate these IPs to have it be included. According to my understanding, the EDLs are updated via 3rd party vendors, not Palo themselves. That said, these IPs are not well-known for being malicious, even other major vendors like Forti does not categories these as malicious yet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is this correct or is there a way to engage with Palo to review these IPs and have then included in the Palo EDLs?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Apr 2025 11:24:38 GMT</pubDate>
    <dc:creator>R.Bester</dc:creator>
    <dc:date>2025-04-09T11:24:38Z</dc:date>
    <item>
      <title>Palo EDL list - some malicious IPs not included</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/palo-edl-list-some-malicious-ips-not-included/m-p/1226074#M2990</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just want to make sure I understand Palo's EDL's correctly: a client has a query about 3 IP addresses that are not included in Palo's EDL, but is picked up as malicious via Virus Total and MXToolbox&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;138.199.15.177&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;179.43.149.114&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;45.148.10.237&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The client wants to know why these specific IPs are not present in the EDLs and want's Palo to investigate these IPs to have it be included. According to my understanding, the EDLs are updated via 3rd party vendors, not Palo themselves. That said, these IPs are not well-known for being malicious, even other major vendors like Forti does not categories these as malicious yet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is this correct or is there a way to engage with Palo to review these IPs and have then included in the Palo EDLs?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 11:24:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/palo-edl-list-some-malicious-ips-not-included/m-p/1226074#M2990</guid>
      <dc:creator>R.Bester</dc:creator>
      <dc:date>2025-04-09T11:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: Palo EDL list - some malicious IPs not included</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/palo-edl-list-some-malicious-ips-not-included/m-p/1226177#M2991</link>
      <description>&lt;P&gt;Hi &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1065763159"&gt;@R.Bester&lt;/a&gt;&lt;/SPAN&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If an IP isn’t included in an EDL, it likely just hasn’t met the criteria for inclusion by the list’s owner whether it is from PAN or a third-party.&lt;/P&gt;
&lt;P&gt;Do you know which specific EDL you’re referring to and who manages it? If it’s one of Palo’s predefined EDLs, you can open a support ticket to raise the concern and request a review of those IPs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, if you’ve already found strong evidence that certain IPs are malicious, you don’t have to wait. You can easily create and host your own custom EDL that you can reference in your security policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDLs are great to supplement your threat detection, but they shouldn't be the only layer of defense when you come across IPs/domains you would like to block.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 05:57:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/palo-edl-list-some-malicious-ips-not-included/m-p/1226177#M2991</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-04-10T05:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Palo EDL list - some malicious IPs not included</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/palo-edl-list-some-malicious-ips-not-included/m-p/1226549#M2993</link>
      <description>&lt;P&gt;Thanks for the reply Jay, I assume it's going to be TAC case if I want put in a request for Palo to review the IPs? Or is there an alternative method to create a 'Threat case'?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 11:41:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/palo-edl-list-some-malicious-ips-not-included/m-p/1226549#M2993</guid>
      <dc:creator>R.Bester</dc:creator>
      <dc:date>2025-04-15T11:41:25Z</dc:date>
    </item>
  </channel>
</rss>

