<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File Types and Md5 Hashes in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/file-types-and-md5-hashes/m-p/15373#M11288</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem will be to capture all the file's stream. With the palo, you're only be able to capture stream if threat is indentify in it and only on a the "infected" part of stream.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the SHA256 hash is calculate when creating a forwarding profile for wildfire. May be possible to retrieve it through the API ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Jul 2013 07:32:55 GMT</pubDate>
    <dc:creator>VinceM</dc:creator>
    <dc:date>2013-07-08T07:32:55Z</dc:date>
    <item>
      <title>File Types and Md5 Hashes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-types-and-md5-hashes/m-p/15370#M11285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I write SIEM content (Mostly Arcsight and Q1), I have found PAN to be very effective in identifying adverse traffic. One thing that would be great, that in addition to recognizing the file type such as "file Microsoft PE File(52060)" which is useful as a poor mans DLP, with which I can track whats coming and going, it's only so effective by just having the file name. It would be much more effective if the md5 hash value of the file was written to the log file. Then I can correlate the log file md5 hash with my known bad hash database....Can this be done, is it there and I have missed it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 16:10:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-types-and-md5-hashes/m-p/15370#M11285</guid>
      <dc:creator>scottlsattler</dc:creator>
      <dc:date>2013-07-02T16:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: File Types and Md5 Hashes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-types-and-md5-hashes/m-p/15371#M11286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately No.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Palo Alto will not buffer through the entire file in order to get the hash of the file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you are using Wildfire to forward certain file types to the wildfire portal, it will give you the SHA for the file but not MD5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this is helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 16:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-types-and-md5-hashes/m-p/15371#M11286</guid>
      <dc:creator>Chatri</dc:creator>
      <dc:date>2013-07-02T16:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: File Types and Md5 Hashes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-types-and-md5-hashes/m-p/15372#M11287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wouldnt it still be possible to create a md5 of a stream since md5 works with 512bit blocks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://en.wikipedia.org/wiki/Cryptographic_hash_function" title="http://en.wikipedia.org/wiki/Cryptographic_hash_function"&gt;Cryptographic hash function - Wikipedia, the free encyclopedia&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://en.wikipedia.org/wiki/Md5" title="http://en.wikipedia.org/wiki/Md5"&gt;MD5 - Wikipedia, the free encyclopedia&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 18:29:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-types-and-md5-hashes/m-p/15372#M11287</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-07-04T18:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: File Types and Md5 Hashes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/file-types-and-md5-hashes/m-p/15373#M11288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem will be to capture all the file's stream. With the palo, you're only be able to capture stream if threat is indentify in it and only on a the "infected" part of stream.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the SHA256 hash is calculate when creating a forwarding profile for wildfire. May be possible to retrieve it through the API ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 07:32:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/file-types-and-md5-hashes/m-p/15373#M11288</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-07-08T07:32:55Z</dc:date>
    </item>
  </channel>
</rss>

