<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Submit IP to known malicious IP or High Risk IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/490909#M104930</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm sure you can open a ticket and enter all of you evidence. What I do is just setup my telemetry to send to PAN so they make the calls that way. Since your PAN should be blocking it, honestly playing IP whack a mole is tough and not really worth the effort. Submit a ticket to the owner abuse email address?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2022 19:11:02 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2022-05-24T19:11:02Z</dc:date>
    <item>
      <title>Submit IP to known malicious IP or High Risk IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/490835#M104922</link>
      <description>&lt;P&gt;Can an IP be submitted to Palo Alto to be included in the high-risk or known-malicious IP address lists? We have an IP that has been discovered to be a major DDOS attack BOT coordination point but it's not listed in PAN's threat vault and is not being blocked by our IP list block rules. Talos and other sites lists this as a high risk IP but I'm not seeing anyway to get it on PANs list short of trying to deliver some questionable traffic to the IP and hope that Wildfire picks it up.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 17:28:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/490835#M104922</guid>
      <dc:creator>JoshuaSanders</dc:creator>
      <dc:date>2022-05-24T17:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: Submit IP to known malicious IP or High Risk IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/490909#M104930</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm sure you can open a ticket and enter all of you evidence. What I do is just setup my telemetry to send to PAN so they make the calls that way. Since your PAN should be blocking it, honestly playing IP whack a mole is tough and not really worth the effort. Submit a ticket to the owner abuse email address?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 19:11:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/490909#M104930</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-05-24T19:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Submit IP to known malicious IP or High Risk IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/503637#M105444</link>
      <description>&lt;P&gt;How are you sending your telemetry to PAN?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 18:01:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/503637#M105444</guid>
      <dc:creator>JoshuaSanders</dc:creator>
      <dc:date>2022-06-14T18:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Submit IP to known malicious IP or High Risk IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/503695#M105448</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131761"&gt;@JoshuaSanders&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;There's not a process for customers to request an IP get added to either of these lists. I'd recommend setting up something that you can easily feed into the firewall for manual IP blocking in cases like this. That can be a manual blacklist entry that you manually update, or you could setup an EDL that can be dynamically updated on a schedule on the firewall so you aren't having to commit just to block an address.&lt;/P&gt;
&lt;P&gt;As for sending telemetry to the firewall, you can review the documentation on that &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/share-threat-intelligence-with-palo-alto-networks/enable-telemetry" target="_self"&gt;HERE&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 02:31:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/503695#M105448</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-06-15T02:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Submit IP to known malicious IP or High Risk IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/585001#M116799</link>
      <description>&lt;P&gt;I found an IP in our logs that has been scanning our network lately. I do not see the IP address in any of the PA Predefined External Dynamic Lists (I.e. Tor Exist IP Address, Bulletproof IP, etc.). However, I do see it on&amp;nbsp;&lt;A href="https://www.abuseipdb.com/" target="_blank"&gt;https://www.abuseipdb.com/&lt;/A&gt;&amp;nbsp;as a repeat offender.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestions on what URL I could use to pull the this IP address.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 01:39:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/submit-ip-to-known-malicious-ip-or-high-risk-ip/m-p/585001#M116799</guid>
      <dc:creator>Tim_Stephens</dc:creator>
      <dc:date>2024-04-26T01:39:16Z</dc:date>
    </item>
  </channel>
</rss>

