<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default threat ID correlation for action in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47998#M35292</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/28351"&gt;craigmueller&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link you are looking for :&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1367"&gt;Trigger Conditions for Brute Force Signatures&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Jun 2014 21:07:14 GMT</pubDate>
    <dc:creator>kadak</dc:creator>
    <dc:date>2014-06-30T21:07:14Z</dc:date>
    <item>
      <title>Default threat ID correlation for action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47994#M35288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was searching for a while and could not find the answer to this question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default, does a Palo Alto block every instance a threat ID (that is enabled) is seen or does it wait until 1 threat ID hits 5 times in 1 minute (for example).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would think it would be the former, but was searching for confirmation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 19:34:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47994#M35288</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-06-30T19:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Default threat ID correlation for action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47995#M35289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If threat ID has default action RESET than it will stop in first instance. So, it depends on default action of threat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a different case in Vulnerability. Lets say there is a vuln. for bruteforce. And Palo Alto conclude it bruteforce if there are more than 60 attempts in 1 minutes. So in these type of scenarios we check the hits. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best thing is to understand threat details, firewall will behave case to case bases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 20:58:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47995#M35289</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-06-30T20:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Default threat ID correlation for action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47996#M35290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hardik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's take HTTP Unauthorized Brute-force Attack (40031) for example and it's set to the default action of allow. You are saying, there would have to be 60 attempts within 1 minute before an alert would be created?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a link to these figures?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 21:03:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47996#M35290</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-06-30T21:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: Default threat ID correlation for action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47997#M35291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right about the behavior, certain number of attempts within 1 minute can trigger vulnerability 40031. And it will only generate a Threat log, because default action is Alert, not Reset.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 21:07:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47997#M35291</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-06-30T21:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Default threat ID correlation for action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47998#M35292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/28351"&gt;craigmueller&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link you are looking for :&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1367"&gt;Trigger Conditions for Brute Force Signatures&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 21:07:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47998#M35292</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2014-06-30T21:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: Default threat ID correlation for action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47999#M35293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there separate lists for each group of signatures? Like 40022 or 40008.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 21:15:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/47999#M35293</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-06-30T21:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Default threat ID correlation for action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/48000#M35294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There may not be, but why do you need it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 22:22:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/48000#M35294</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-06-30T22:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Default threat ID correlation for action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/48001#M35295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was looking for more information on the threat IDs and what triggers the alerts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 22:24:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/48001#M35295</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-06-30T22:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Default threat ID correlation for action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/48002#M35296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally PAN doesnt disclose that information unless asked by specific customer for specific ID. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 22:43:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/48002#M35296</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-06-30T22:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Default threat ID correlation for action</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/48003#M35297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, thanks everyone for the information&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 22:45:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-threat-id-correlation-for-action/m-p/48003#M35297</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-06-30T22:45:24Z</dc:date>
    </item>
  </channel>
</rss>

