<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic why hacktool vulnerability is set to medium action alert? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-hacktool-vulnerability-is-set-to-medium-action-alert/m-p/454253#M101443</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've been looking a history entries in our threat log and it seems to me that most of the default settings for vulnerabilities - "action" are set to low, for example to "alert" - although they classify the threat as "medium" or "high". For example in the screenshot below the threat of this hacktool is set to "alert". Shouldn't this be a set at east to a drop\reset, etc or something that doesn't allow it? What's Palo's thinking behind this?&lt;/P&gt;&lt;P&gt;Thanks.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture11.JPG" style="width: 364px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38223i7A75B481607D9F04/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture11.JPG" alt="Capture11.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 19 Dec 2021 19:43:15 GMT</pubDate>
    <dc:creator>roma</dc:creator>
    <dc:date>2021-12-19T19:43:15Z</dc:date>
    <item>
      <title>why hacktool vulnerability is set to medium action alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-hacktool-vulnerability-is-set-to-medium-action-alert/m-p/454253#M101443</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've been looking a history entries in our threat log and it seems to me that most of the default settings for vulnerabilities - "action" are set to low, for example to "alert" - although they classify the threat as "medium" or "high". For example in the screenshot below the threat of this hacktool is set to "alert". Shouldn't this be a set at east to a drop\reset, etc or something that doesn't allow it? What's Palo's thinking behind this?&lt;/P&gt;&lt;P&gt;Thanks.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture11.JPG" style="width: 364px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38223i7A75B481607D9F04/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture11.JPG" alt="Capture11.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Dec 2021 19:43:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-hacktool-vulnerability-is-set-to-medium-action-alert/m-p/454253#M101443</guid>
      <dc:creator>roma</dc:creator>
      <dc:date>2021-12-19T19:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: why hacktool vulnerability is set to medium action alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-hacktool-vulnerability-is-set-to-medium-action-alert/m-p/454482#M101471</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;There are legitimate use cases for this software. Palo Alto at times takes a conservative approach as not to break things and allow the end users to customize it for their needs. I always set anything medium and higher to be blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 21:15:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-hacktool-vulnerability-is-set-to-medium-action-alert/m-p/454482#M101471</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-20T21:15:03Z</dc:date>
    </item>
  </channel>
</rss>

