<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to allowlist a file form wildfire-virus in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1238321#M125173</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;I think that makes sense. How then do you create an exclusion for the "&lt;SPAN&gt;wildfire-virus" type detections?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Sep 2025 15:32:07 GMT</pubDate>
    <dc:creator>Verac22</dc:creator>
    <dc:date>2025-09-18T15:32:07Z</dc:date>
    <item>
      <title>How to allowlist a file form wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1237796#M125106</link>
      <description>&lt;P&gt;We have a file (Filex.exe) that is throwing blocks of the following type&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="x-grid3-row  x-grid3-row-first "&gt;
&lt;TABLE class="x-grid3-row-table" border="0" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-id2  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Threat Type&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-3  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;wildfire-virus&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;DIV class="x-grid3-row "&gt;
&lt;TABLE class="x-grid3-row-table" border="0" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-id2  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;Threat ID/Name&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-3  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;trojan/Win32 EXE.crypt.aexg&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;DIV class="x-grid3-row "&gt;
&lt;TABLE class="x-grid3-row-table" border="0" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-id2  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-id2"&gt;ID&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="x-grid3-col x-grid3-cell x-grid3-td-3  x-grid-selectable"&gt;
&lt;DIV class="x-grid3-cell-inner x-grid3-col-3"&gt;213019932 (&lt;A href="https://threatvault.paloaltonetworks.com/?query=213019932" target="_blank" rel="noopener"&gt;View in Threat Vault&lt;/A&gt;)&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do I add this exclude this file from alerting? I went into Object &amp;gt; Security Objects &amp;gt; Antivirus &amp;gt; the profile &amp;gt; Wildfire Inline ML, and I added the file name and partial hash (not sure I fully understand partial hash. I used the first 31 characters of the sha256). We are still getting alerts for this file though.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 Sep 2025 19:30:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1237796#M125106</guid>
      <dc:creator>Verac22</dc:creator>
      <dc:date>2025-09-11T19:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to allowlist a file form wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1237858#M125107</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275773"&gt;@Verac22&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like the threat type is identified as "wildfire-virus" and not as "ml-virus".&lt;/P&gt;
&lt;P&gt;There's a nuance in both of these threat types as far as I know:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The wildfire-virus threat type comes from a verdict issued by the WildFire cloud analysis. This is a definitive, file-based verdict.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The ml-virus threat type comes from the inline machine learning engine on the firewall&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The exception you created on the WildFire Inline ML page only applies to detections made by the inline engine (ml-virus threats). Since the file was categorized as a wildfire-virus by the cloud, the local exception was bypassed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's the KB talking about it:&lt;BR /&gt;&lt;A title="How to set a File exception or disable WildFire Inline ML model" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000bpylCAA&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener"&gt;How to set a File exception or disable WildFire Inline ML model&lt;/A&gt;&amp;nbsp; (ml-virus threat types)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2025 08:18:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1237858#M125107</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-09-12T08:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to allowlist a file form wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1238321#M125173</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;I think that makes sense. How then do you create an exclusion for the "&lt;SPAN&gt;wildfire-virus" type detections?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 15:32:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1238321#M125173</guid>
      <dc:creator>Verac22</dc:creator>
      <dc:date>2025-09-18T15:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to allowlist a file form wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1238332#M125175</link>
      <description>&lt;P&gt;If you are sure that the file is not malicious, then you can set the exception in the "Signature Exceptions" tab using the Threat ID "213019932".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;References:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcrCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcrCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/advanced-threat-prevention/administration/configure-threat-prevention/create-threat-exceptions#id566b52a9-d584-47f1-9c1d-f33814fe3c48" target="_blank"&gt;https://docs.paloaltonetworks.com/advanced-threat-prevention/administration/configure-threat-prevention/create-threat-exceptions#id566b52a9-d584-47f1-9c1d-f33814fe3c48&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2025 00:23:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1238332#M125175</guid>
      <dc:creator>ymiyashita</dc:creator>
      <dc:date>2025-09-19T00:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to allowlist a file form wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1238827#M125226</link>
      <description>&lt;P&gt;So that allows us to exclude the entire signature. But is there no way to only exclude the particular file by hash or name?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 20:02:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1238827#M125226</guid>
      <dc:creator>Verac22</dc:creator>
      <dc:date>2025-09-25T20:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to allowlist a file form wildfire-virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1238828#M125227</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275773"&gt;@Verac22&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The way to handle this really is by reporting the incorrect verdict so that it is corrected and no longer triggers. There's not a way to exclude just that one single hash unless it's an inline detection; the closets you can get to that is creating a specific profile with the threat signature excluded and associating it with a dedicated rule where that file would be matching. Obviously that doesn't mean it will only ever match that one file, but you've created the smallest possible exception as what you can currently with PAN-OS.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 20:51:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-allowlist-a-file-form-wildfire-virus/m-p/1238828#M125227</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-09-25T20:51:41Z</dc:date>
    </item>
  </channel>
</rss>

