<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How Palo alto detect virus in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44461#M32628</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Other things to take into account (if the download actually passed the PA) is if ssl was used or not and if so did you have ssl-decryption enabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you have a copy of the malicious file you could try to upload it manually to wildfire and see which opinion wildfire has on the file in question (first login to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://support.paloaltonetworks.com):"&gt;https://support.paloaltonetworks.com):&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://wildfire.paloaltonetworks.com/" title="https://wildfire.paloaltonetworks.com/"&gt;https://wildfire.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Jul 2013 18:12:41 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-07-04T18:12:41Z</dc:date>
    <item>
      <title>How Palo alto detect virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44457#M32624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps"&gt;Last week&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;my client&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;suffered&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;a virus&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;attack&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;in&lt;/SPAN&gt; its &lt;SPAN class="hps"&gt;LAN&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;&lt;/SPAN&gt;&lt;SPAN class="hps"&gt;and we have not&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;seen anything&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;in&lt;/SPAN&gt; P&lt;SPAN class="hps"&gt;alo Alto (monitor threat)&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;I wanted to know&lt;/SPAN&gt; how good is Palo Alto detecting virus and why reasons the PA didnt detect this virus. Anyone has had any similar problem&lt;SPAN class="hps"&gt;&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN&gt;thanks a lot&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 11:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44457#M32624</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-07-04T11:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo alto detect virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44458#M32625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can search for the virus that you found with other vendor or etc.. using &lt;A class="active_link" href="https://threatvault.paloaltonetworks.com/" title="https://threatvault.paloaltonetworks.com/"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;maybe there is no signature for that or maybe it is false positive for PaloAlto.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 11:15:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44458#M32625</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-04T11:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo alto detect virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44459#M32626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe virus didn't go through the palo or using a rule with no security profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;v.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 12:51:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44459#M32626</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-07-04T12:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo alto detect virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44460#M32627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have the traffic logs, and the information about the virus? In cases where the attack could have been a zero day attack, we can use the wildfire functionanlity of the PANFW to report unknown signatures to the cloud, analyze these signatures and determine if they are malicious or not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 14:11:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44460#M32627</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-07-04T14:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo alto detect virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44461#M32628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Other things to take into account (if the download actually passed the PA) is if ssl was used or not and if so did you have ssl-decryption enabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you have a copy of the malicious file you could try to upload it manually to wildfire and see which opinion wildfire has on the file in question (first login to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://support.paloaltonetworks.com):"&gt;https://support.paloaltonetworks.com):&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://wildfire.paloaltonetworks.com/" title="https://wildfire.paloaltonetworks.com/"&gt;https://wildfire.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 18:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44461#M32628</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-07-04T18:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo alto detect virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44462#M32629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A __default_attr="5454" __jive_macro_name="user" class="jive_macro jive_macro_user" data-objecttype="3" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; can you please reply? You had a few different people who have had the courtesy of asking you for more information in this thread that you started who are trying to help you...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 00:09:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44462#M32629</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-07-26T00:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo alto detect virus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44463#M32630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DOS protection and Zone protection is typically applied for attacks.&lt;/P&gt;&lt;P&gt;Make sure to apply DOS protection to the security rule.&lt;/P&gt;&lt;P&gt;Zone protection profile needs to be assigned to respective Zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure the content is uptodate and security rules are using AV, Vulnerability profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you find some virus which was not covered, pcaps/relevant URLs can be submitted to add the coverage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wildfire can be configured which can help us identify the suspicious traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 19:35:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-detect-virus/m-p/44463#M32630</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2013-07-26T19:35:10Z</dc:date>
    </item>
  </channel>
</rss>

