<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data filter - Blocking suspicious downloads in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/data-filter-blocking-suspicious-downloads/m-p/40216#M29502</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; For data filtering we set a rule to alert for certain downloads (such as .bat, .exe, etc).&amp;nbsp; In the monitor log, all alerts are listed as LOW severity.&amp;nbsp; I have noticed a pattern where a workstation shows a suspicious download such as game.exe or abyzdew.exe (random letters in name) and then starts showing outbound spyware or virus messages.&amp;nbsp; My deduction is the download was some type of malware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to have the files being downloaded scanned for malware and alerted in the data filter tab?&amp;nbsp; What is the purpose of the severity column in the data filtering tab as it relates to the "FILE" type of data filter and why does it always show as low.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Crill&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Nov 2010 12:43:20 GMT</pubDate>
    <dc:creator>merrydc</dc:creator>
    <dc:date>2010-11-02T12:43:20Z</dc:date>
    <item>
      <title>Data filter - Blocking suspicious downloads</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-filter-blocking-suspicious-downloads/m-p/40216#M29502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; For data filtering we set a rule to alert for certain downloads (such as .bat, .exe, etc).&amp;nbsp; In the monitor log, all alerts are listed as LOW severity.&amp;nbsp; I have noticed a pattern where a workstation shows a suspicious download such as game.exe or abyzdew.exe (random letters in name) and then starts showing outbound spyware or virus messages.&amp;nbsp; My deduction is the download was some type of malware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to have the files being downloaded scanned for malware and alerted in the data filter tab?&amp;nbsp; What is the purpose of the severity column in the data filtering tab as it relates to the "FILE" type of data filter and why does it always show as low.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Crill&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 12:43:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-filter-blocking-suspicious-downloads/m-p/40216#M29502</guid>
      <dc:creator>merrydc</dc:creator>
      <dc:date>2010-11-02T12:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: Data filter - Blocking suspicious downloads</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/data-filter-blocking-suspicious-downloads/m-p/40217#M29503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;For data filtering we set a rule to alert for certain downloads (such as .bat, .exe, etc).&amp;nbsp; In the monitor log, all alerts are listed as LOW &amp;gt;severity.&amp;nbsp; I have noticed a pattern where a workstation shows a suspicious download such as game.exe or abyzdew.exe (random letters &amp;gt;in name) and then starts showing outbound spyware or virus messages.&amp;nbsp; My deduction is the download was some type of malware.&lt;/P&gt;&lt;P&gt; &amp;gt;Is there a way to have the files being downloaded scanned for malware and alerted in the data filter tab?&amp;nbsp; What is the purpose of the&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Downloaded files will be scanned for malware through antivirus profile (Objects-&amp;gt;Security Profiles -&amp;gt; Antivirus). Corresponding logs are generated in 'Threat' Log. If you click on the log, it will also show corresponding logs for the 'same' session from different log databases e.g, if a file blocking profile also got triggered on the file, you will see that log when you click on the virus log in the threat log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;severity column in the data filtering tab as it relates to the "FILE" type of data filter and why does it always show as low.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently, all file blocking logs show up as 'low' severity. Let me know if you have some suggestions on how you would like to see this in a future release (Also, please work through your Sales Engineer/Reseller to have them open a feature request for better tracking). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any further questions,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Sandeep &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;gt;Crill&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 17:54:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/data-filter-blocking-suspicious-downloads/m-p/40217#M29503</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-11-02T17:54:24Z</dc:date>
    </item>
  </channel>
</rss>

