<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire flow in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-flow/m-p/2614#M1948</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are uploaded files stored somewhere within this "cloud" to be re-evaluated on a schedule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im thinking when PA is changing what will trigger a file to be considered malware or not (like the case I found a few months ago where wildfire verdict was benign but the file was truly a very bad file) - then this "the hash matches a clean file" might not be true...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also is there a setting regarding this within WF-500, for example making a verdict for a specific hash only valid for 24 hours or so - if the file is seen again later on then the file will be re-evaluated?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 22 Sep 2013 10:47:37 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-09-22T10:47:37Z</dc:date>
    <item>
      <title>Wildfire flow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-flow/m-p/2612#M1946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the desicion flow of wildfire, where is the hash update and wildfire database update ? can someone tell the real place of both in that chart.&lt;/P&gt;&lt;P&gt;Document's very clear but it is written before subscription service was released.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3555"&gt;WildFire Decision Flow&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Sep 2013 12:53:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-flow/m-p/2612#M1946</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-09-21T12:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire flow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-flow/m-p/2613#M1947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;When users download .exe or .dll files, PA computes the hash of the file and send only computed hash to the wildfire cloud. Then in the cloud, this hash is compared with the hash base which is maintained by palaltonetworks. If the hash matches, then the verdict is known and file is not uploaded to the cloud, if hash do not match then the file is uploaded and inspected and you can see the file on the portal. Also if the hash on the PA doesnt match with the hash database in the cloud, it creates a new virus id for the file. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed R Hasnain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Sep 2013 16:06:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-flow/m-p/2613#M1947</guid>
      <dc:creator>shasnain</dc:creator>
      <dc:date>2013-09-21T16:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire flow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-flow/m-p/2614#M1948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are uploaded files stored somewhere within this "cloud" to be re-evaluated on a schedule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im thinking when PA is changing what will trigger a file to be considered malware or not (like the case I found a few months ago where wildfire verdict was benign but the file was truly a very bad file) - then this "the hash matches a clean file" might not be true...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also is there a setting regarding this within WF-500, for example making a verdict for a specific hash only valid for 24 hours or so - if the file is seen again later on then the file will be re-evaluated?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Sep 2013 10:47:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-flow/m-p/2614#M1948</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-09-22T10:47:37Z</dc:date>
    </item>
  </channel>
</rss>

