<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspicious DNS Query list in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-list/m-p/50804#M37378</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your replies.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Aug 2014 14:40:41 GMT</pubDate>
    <dc:creator>craigmueller</dc:creator>
    <dc:date>2014-08-18T14:40:41Z</dc:date>
    <item>
      <title>Suspicious DNS Query list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-list/m-p/50801#M37375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a list of all the DNS Querys that PA considers suspicious?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was considering changing the default action from alert to block for these signatures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since there is potentially 1 million URLs that will automatically get blocked when adjusted, my client might want to go over the list before making the decision.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PA DNS Sig.JPG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14986_PA DNS Sig.JPG" style="height: 391px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Aug 2014 21:06:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-list/m-p/50801#M37375</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-08-15T21:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-list/m-p/50802#M37376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That list is a "living database" and changes over time.&amp;nbsp; I think a better method to use with your customer would be to understand "what would have been blocked".&amp;nbsp; You can run a simple custom report to answer that question.&amp;nbsp; Use the "Threat Log" as your data source and use the following options (feel free to change your timeframe - just keep in mind the longer the timeframe the longer the report may take to run.&amp;nbsp; Start small ~1 day and then work your way up).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2014-08-15 at 3.18.47 PM.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14987_Screen Shot 2014-08-15 at 3.18.47 PM.png" style="height: 344px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;In my small lab environment, the output looks like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2014-08-15 at 3.22.22 PM.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14988_Screen Shot 2014-08-15 at 3.22.22 PM.png" style="height: 176px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Aug 2014 21:24:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-list/m-p/50802#M37376</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2014-08-15T21:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-list/m-p/50803#M37377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Jared.&amp;nbsp; Even if you could see the whole database, and the chances are low that PA would allow that.&amp;nbsp; I'm sure they consider those contents a trade secret they want to keep from the competition, the report is more relevant. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The report tells you what your users are likely to see on your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember also that generally when a default action is to alert instead of block, there is a much higher possibility of a false positive.&amp;nbsp; So you may generate some work allowing blocked sites after the action is changed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2014 00:17:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-list/m-p/50803#M37377</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-08-16T00:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious DNS Query list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-list/m-p/50804#M37378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your replies.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2014 14:40:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-dns-query-list/m-p/50804#M37378</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-08-18T14:40:41Z</dc:date>
    </item>
  </channel>
</rss>

