<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Verdict &amp;quot;malicious&amp;quot;  and action &amp;quot;allow&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/586478#M117039</link>
    <description>&lt;P&gt;Hi team&lt;/P&gt;
&lt;P&gt;We are detecting some files with&amp;nbsp;Verdict "malicious" and action "allow"&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Alpalo_0-1715594709155.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59636i0DA278BD6AB061F9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Alpalo_0-1715594709155.png" alt="Alpalo_0-1715594709155.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Can anybody help us for change the action or other solution?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 May 2024 10:06:14 GMT</pubDate>
    <dc:creator>Alpalo</dc:creator>
    <dc:date>2024-05-13T10:06:14Z</dc:date>
    <item>
      <title>Verdict "malicious"  and action "allow"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/586478#M117039</link>
      <description>&lt;P&gt;Hi team&lt;/P&gt;
&lt;P&gt;We are detecting some files with&amp;nbsp;Verdict "malicious" and action "allow"&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Alpalo_0-1715594709155.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59636i0DA278BD6AB061F9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Alpalo_0-1715594709155.png" alt="Alpalo_0-1715594709155.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Can anybody help us for change the action or other solution?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 10:06:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/586478#M117039</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2024-05-13T10:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Verdict "malicious"  and action "allow"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/586493#M117044</link>
      <description>&lt;P&gt;WildFire log?&lt;/P&gt;
&lt;P&gt;If you click on the magnifying glass, WildFire Analysis Report tab then what does "First Seen Timestamp" show?&lt;/P&gt;
&lt;P&gt;WildFire will pass through the malicious file on first instance it sees the file and when verdict comes back from the sandbox it will show if verdict was benign or not. So in those cases you need to analyze workstation to check if it got infected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Starting from 11.0.2 there is new feature "Hold Mode for WildFire Real-Time Signature Lookup"&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/wildfire-features/hold-mode-for-wildfire-realtime-signature-lookup" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/wildfire-features/hold-mode-for-wildfire-realtime-signature-lookup&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 12:51:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/586493#M117044</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-05-13T12:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Verdict "malicious"  and action "allow"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/587362#M117183</link>
      <description>&lt;P&gt;We have wildfire real-time configured and the action is reset-both but we are seeing that the first time the veredict is benign, one the signature is created the veredict changes to malicious but the result keeps being "allow", Is that correct? Is there any way to block this malicious files?&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 07:41:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/587362#M117183</guid>
      <dc:creator>JuanMAbellan</dc:creator>
      <dc:date>2024-05-21T07:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Verdict "malicious"  and action "allow"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/587382#M117185</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/299679"&gt;@JuanMAbellan&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is expected.&amp;nbsp; Please check into the feature &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/wildfire-features/hold-mode-for-wildfire-realtime-signature-lookup" target="_blank" rel="noopener"&gt;Hold Mode for WildFire Real-Time Signature Lookup&lt;/A&gt; as mentioned by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt; .&lt;/P&gt;
&lt;P&gt;With this feature you can prevent the initial transfer of known malware.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 11:27:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/verdict-quot-malicious-quot-and-action-quot-allow-quot/m-p/587382#M117185</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-05-21T11:27:32Z</dc:date>
    </item>
  </channel>
</rss>

