<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I block files by signature? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-block-files-by-signature/m-p/47159#M34669</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the use case? It seems like managing a list of file hashes would be a daunting task since it would be outdated very quickly, if not almost immediately. (This is the biggest reason why Wildfire signatures don't block based on file hash as some of our competitors do, but are actually a signature written to block the malicious code. This way when the file hash changes the signature is not immediately ineffective)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Jun 2015 15:57:12 GMT</pubDate>
    <dc:creator>mlutgen</dc:creator>
    <dc:date>2015-06-25T15:57:12Z</dc:date>
    <item>
      <title>Can I block files by signature?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-block-files-by-signature/m-p/47157#M34667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had a client ask if I could block files by hash.&amp;nbsp; Without additional information -- such as what protocol, application, host, user-agent, etc. -- it wouldn't be possible to do this with a threat signature, so how else could it be done?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Corey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/27904"&gt;mlutgen&lt;/A&gt; &lt;A href="https://live.paloaltonetworks.com/u1/2105"&gt;Brad Spilde&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2015 20:29:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-block-files-by-signature/m-p/47157#M34667</guid>
      <dc:creator>CoreySteele</dc:creator>
      <dc:date>2015-06-24T20:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can I block files by signature?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-block-files-by-signature/m-p/47158#M34668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Corey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's no mechanism to block by file hash. The hash is calculated when uploading to WildFire and is used in that context only. There is no hook into policy to control (block, allow, scan, etc.) by hash value. Adding such a function would need to be submitted as a feature request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Greg Wesson&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2015 23:34:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-block-files-by-signature/m-p/47158#M34668</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-06-24T23:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can I block files by signature?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-block-files-by-signature/m-p/47159#M34669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the use case? It seems like managing a list of file hashes would be a daunting task since it would be outdated very quickly, if not almost immediately. (This is the biggest reason why Wildfire signatures don't block based on file hash as some of our competitors do, but are actually a signature written to block the malicious code. This way when the file hash changes the signature is not immediately ineffective)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2015 15:57:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-block-files-by-signature/m-p/47159#M34669</guid>
      <dc:creator>mlutgen</dc:creator>
      <dc:date>2015-06-25T15:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can I block files by signature?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-block-files-by-signature/m-p/47160#M34670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some of my customers get lists of hashes of files that are bad but that don't show up in antivirus or malware detection systems.&amp;nbsp; E.g. from DHS, FS-ISAC, etc.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point is, the protections available to me via a PA are essentially wildfire (i.e. hoping someone else gets hit before me), or threat protection (e.g. antivirus and IDS signatures).&amp;nbsp; But if neither of those catch the bad thing, I'm boned.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-C&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2015 17:20:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-block-files-by-signature/m-p/47160#M34670</guid>
      <dc:creator>CoreySteele</dc:creator>
      <dc:date>2015-06-25T17:20:33Z</dc:date>
    </item>
  </channel>
</rss>

