<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire file exceptions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-file-exceptions/m-p/19970#M14548</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt; thank you for the information.&amp;nbsp; From what I am seeing in the threat logs, the ID is unique to each exception, and cannot possibly capture each one in a single exception.&amp;nbsp; Can you provide a bit more detail on the Threat ID, to ensure I am looking at the right information?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Aug 2013 12:22:27 GMT</pubDate>
    <dc:creator>jholmes</dc:creator>
    <dc:date>2013-08-22T12:22:27Z</dc:date>
    <item>
      <title>Wildfire file exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-file-exceptions/m-p/19968#M14546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey everyone, sorry if this was posted before and missed it in searching.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am receiving an enormous number of alerts from Wildfire, due to an internal application that our desktop engineering created.&amp;nbsp; Its more or less is just an exe that creates short cuts to our internal HR portal, which Wildfire believes to be malware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am looking for is a way that I can still continue to send up all PE files to Wildfire, but create an exception list of items that are known to be good, or can be flagged as benign like a trusted file.&amp;nbsp; I am sure that I will run across this more and more, as we do a lot of custom packaging in our environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jeremy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Aug 2013 18:38:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-file-exceptions/m-p/19968#M14546</guid>
      <dc:creator>jholmes</dc:creator>
      <dc:date>2013-08-21T18:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire file exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-file-exceptions/m-p/19969#M14547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please collect&amp;nbsp; threat ID from the PA firewall logs, which is generated by the PA due to that EXE file and PA firewall believes as a malware. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Put that ID and search under "Exceptions" TAB&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Set appropriate action for it.&lt;/P&gt;&lt;P&gt;3. OK and commit the changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example: &lt;A href="https://live.paloaltonetworks.com/message/26273"&gt;Re: Adding Threat Exceptions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/message/12408"&gt;Still no way to set SPECIFIC threat exceptions???&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/message/20826"&gt;Re: Threat exception for selected hosts&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/message/26494"&gt;Do I Understand Profile Exceptions?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For more info about wildfire, please follow below mentioned &lt;SPAN class="GINGER_SOFATWARE_correct"&gt;document&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3094"&gt;Threat Prevention Deployment Tech Note&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 01:24:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-file-exceptions/m-p/19969#M14547</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-08-22T01:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire file exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-file-exceptions/m-p/19970#M14548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt; thank you for the information.&amp;nbsp; From what I am seeing in the threat logs, the ID is unique to each exception, and cannot possibly capture each one in a single exception.&amp;nbsp; Can you provide a bit more detail on the Threat ID, to ensure I am looking at the right information?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 12:22:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-file-exceptions/m-p/19970#M14548</guid>
      <dc:creator>jholmes</dc:creator>
      <dc:date>2013-08-22T12:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire file exceptions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-file-exceptions/m-p/19971#M14549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is what I ended up doing to fix my situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Created an Address Group for my app deployment servers that were deploying the app.&lt;/P&gt;&lt;P&gt;2. Created 2 security rules in the "Pre" device rules, 1 rule for the app deployment servers as a source and 2nd rule as the app deployment servers as the destinations.&lt;/P&gt;&lt;P&gt;3. Did not associate the rules to a File Blocking profile, so no files coming from these servers get forwarded to Wildfire.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems to be working like a charm, and no further alerts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 15:48:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-file-exceptions/m-p/19971#M14549</guid>
      <dc:creator>jholmes</dc:creator>
      <dc:date>2013-09-09T15:48:56Z</dc:date>
    </item>
  </channel>
</rss>

