<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire Verdict benign / Action block in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-benign-action-block/m-p/1238675#M125214</link>
    <description>&lt;P&gt;Please note the solution provided on this post can cause some confusion as it does not provide a complete picture on how threat prevention works in regards to WF and AV. With that said, Even if the file’s hash is marked as benign by WildFire, if the file still matches an active Antivirus signature, it will continue to be blocked whenever it traverses the firewall.&lt;BR /&gt;In other words, the file's known hash being benign does not override the Antivirus engine. As long as the signature is active and matches the file pattern, the firewall will block it, regardless of the WildFire verdict.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Sep 2025 17:20:53 GMT</pubDate>
    <dc:creator>rnorouzi</dc:creator>
    <dc:date>2025-09-24T17:20:53Z</dc:date>
    <item>
      <title>Wildfire Verdict benign / Action block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-benign-action-block/m-p/233487#M66949</link>
      <description>&lt;P&gt;I'd like to understand how Wildfire works. I have this example where Verdict is benign and action is block. Why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16933i193D478107AEDC4B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA1.png" alt="PA1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA2.png" style="width: 746px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16934iF0B102E7FC6A957E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA2.png" alt="PA2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 22:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-benign-action-block/m-p/233487#M66949</guid>
      <dc:creator>Keny_Schmeling</dc:creator>
      <dc:date>2018-10-02T22:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Verdict benign / Action block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-benign-action-block/m-p/233496#M66950</link>
      <description>&lt;P&gt;Filtering by Session&amp;nbsp;ID&amp;nbsp;I have this logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA3.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16935i95B86F64D96A04E2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA3.png" alt="PA3.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 22:42:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-benign-action-block/m-p/233496#M66950</guid>
      <dc:creator>Keny_Schmeling</dc:creator>
      <dc:date>2018-10-02T22:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Verdict benign / Action block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-benign-action-block/m-p/233703#M66987</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/94148"&gt;@Keny_Schmeling&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What likely happended was the firewall identified the traffic via a signature or local analysis and determined that it was malicious; when it was sent to the wildfire cloud and actually ran in the sandbox environment it was discovered to be benign. Therefore the verdict would report benign, because it is, but the firewall would have blocked the traffic before the file was sent off to be analyzed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now if the hash of the file is seen by your firewall again, it will allow the file as the hash is known to be benign. Likewise, if I attempted to download the same file on my firewall it would also be allowed, because you've already analyzed the file and the hash is known to be benign.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 15:06:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-benign-action-block/m-p/233703#M66987</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-10-03T15:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire Verdict benign / Action block</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-benign-action-block/m-p/1238675#M125214</link>
      <description>&lt;P&gt;Please note the solution provided on this post can cause some confusion as it does not provide a complete picture on how threat prevention works in regards to WF and AV. With that said, Even if the file’s hash is marked as benign by WildFire, if the file still matches an active Antivirus signature, it will continue to be blocked whenever it traverses the firewall.&lt;BR /&gt;In other words, the file's known hash being benign does not override the Antivirus engine. As long as the signature is active and matches the file pattern, the firewall will block it, regardless of the WildFire verdict.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 17:20:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-benign-action-block/m-p/1238675#M125214</guid>
      <dc:creator>rnorouzi</dc:creator>
      <dc:date>2025-09-24T17:20:53Z</dc:date>
    </item>
  </channel>
</rss>

