<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to scan SFTP over SSH  file transfers for virus or malware in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-scan-sftp-over-ssh-file-transfers-for-virus-or-malware/m-p/574341#M115444</link>
    <description>&lt;P&gt;Did your issue resolved?&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jan 2024 18:26:44 GMT</pubDate>
    <dc:creator>SanthoshNarasimula</dc:creator>
    <dc:date>2024-01-24T18:26:44Z</dc:date>
    <item>
      <title>How to scan SFTP over SSH  file transfers for virus or malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-scan-sftp-over-ssh-file-transfers-for-virus-or-malware/m-p/277105#M75421</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just set up SSH decryption, also known as SSH proxy on the palo alto.&lt;/P&gt;&lt;P&gt;When I look at the actual sessions, I do see a checked box near to decrypted, so according to me the decryption itself works.&lt;/P&gt;&lt;P&gt;I also got a warning about a man in the middle attack after I enabled the decryption, because the keys changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now what I want to achieve, is that SFTP file transfers are being scanned for virusses.&lt;/P&gt;&lt;P&gt;I downloaded the eicar.com test file to an external VPS on the internet, and I did SFTP to transfer this eicar.com file to a server I have protected by the palo alto and with SSH proxy decryption enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even though the palo sees the traffic, marks it as decrypted, and on the security antivirus is enabled, the palo does not seem to care about the fact that a virus is being uploaded.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I missing here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the pointers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 19:46:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-scan-sftp-over-ssh-file-transfers-for-virus-or-malware/m-p/277105#M75421</guid>
      <dc:creator>CobaltGroup</dc:creator>
      <dc:date>2019-07-17T19:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to scan SFTP over SSH  file transfers for virus or malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-scan-sftp-over-ssh-file-transfers-for-virus-or-malware/m-p/277213#M75431</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/116733"&gt;@CobaltGroup&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Repeat your test with a WildFire test file that you can download from the WildFire portal. Palo doesn't seem to count eicar files as malicous (because their not) and test with these files I've found to not work reliably as a test with their services.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 03:24:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-scan-sftp-over-ssh-file-transfers-for-virus-or-malware/m-p/277213#M75431</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-18T03:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to scan SFTP over SSH  file transfers for virus or malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-scan-sftp-over-ssh-file-transfers-for-virus-or-malware/m-p/277250#M75437</link>
      <description>&lt;P&gt;I actually did do the test with a couple of different files.&lt;/P&gt;&lt;P&gt;I used the eicar.com file, I use the "wildfire-test-pe-file.exe" file and I downloaded some actual malware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even though I see a hit in the decryption policy, I'm under the impression nothing is being scanned, because in the threats nothing at all shows up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 07:25:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-scan-sftp-over-ssh-file-transfers-for-virus-or-malware/m-p/277250#M75437</guid>
      <dc:creator>CobaltGroup</dc:creator>
      <dc:date>2019-07-18T07:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to scan SFTP over SSH  file transfers for virus or malware</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-scan-sftp-over-ssh-file-transfers-for-virus-or-malware/m-p/574341#M115444</link>
      <description>&lt;P&gt;Did your issue resolved?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 18:26:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-scan-sftp-over-ssh-file-transfers-for-virus-or-malware/m-p/574341#M115444</guid>
      <dc:creator>SanthoshNarasimula</dc:creator>
      <dc:date>2024-01-24T18:26:44Z</dc:date>
    </item>
  </channel>
</rss>

