<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Requirements to alert an threat in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/requirements-to-alert-an-threat/m-p/51507#M37893</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ralf,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding, you will not be able to get the signature source &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;for security reason). Please follow the mentioned link&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;,&lt;/SPAN&gt;you may get some more detailed information: &lt;A href="http://www.welivesecurity.com/2014/02/21/an-in-depth-analysis-of-linuxebury/" title="http://www.welivesecurity.com/2014/02/21/an-in-depth-analysis-of-linuxebury/"&gt;An In-depth Analysis of Linux/Ebury&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Jul 2014 13:56:37 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-07-09T13:56:37Z</dc:date>
    <item>
      <title>Requirements to alert an threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/requirements-to-alert-an-threat/m-p/51506#M37892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there any possibility to get any information about the requirements for detecting an specific threat.&lt;/P&gt;&lt;P&gt;e.g. there is &lt;SPAN style="color: #333333; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 12px;"&gt;Signature ID : 13457&lt;/SPAN&gt; EBURY, what is this signature looking for ?&lt;/P&gt;&lt;P&gt;Do I have to decrypt anything on the PA to give a deeper look into the payload. Is it only examing the DNS traffic ?&lt;/P&gt;&lt;P&gt;Where could get access to the signature source ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Ralf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jul 2014 13:42:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/requirements-to-alert-an-threat/m-p/51506#M37892</guid>
      <dc:creator>ralf_hanl</dc:creator>
      <dc:date>2014-07-09T13:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Requirements to alert an threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/requirements-to-alert-an-threat/m-p/51507#M37893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ralf,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding, you will not be able to get the signature source &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;for security reason). Please follow the mentioned link&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;,&lt;/SPAN&gt;you may get some more detailed information: &lt;A href="http://www.welivesecurity.com/2014/02/21/an-in-depth-analysis-of-linuxebury/" title="http://www.welivesecurity.com/2014/02/21/an-in-depth-analysis-of-linuxebury/"&gt;An In-depth Analysis of Linux/Ebury&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jul 2014 13:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/requirements-to-alert-an-threat/m-p/51507#M37893</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-09T13:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Requirements to alert an threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/requirements-to-alert-an-threat/m-p/51508#M37894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ralf,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default action is set for this threat is "ALEART". Hence, at any point of time if the signature triggers, the PAN firewall will generate a log for the same. GUI &amp;gt; Monitor &amp;gt; Logs &amp;gt; Threat. You may change the default action as mentioned below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Eburry.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14351_Eburry.JPG" style="height: 278px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jul 2014 14:42:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/requirements-to-alert-an-threat/m-p/51508#M37894</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-09T14:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: Requirements to alert an threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/requirements-to-alert-an-threat/m-p/51509#M37895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The basic information that Palo Alto does provide can be found by searching in the Threat Vault.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" title="https://threatvault.paloaltonetworks.com/"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This document shows how to get more detailed information after seeing what is available from Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5316"&gt;How to Find Virus Details if Not Available in the Threat Vault&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jul 2014 23:38:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/requirements-to-alert-an-threat/m-p/51509#M37895</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-07-09T23:38:45Z</dc:date>
    </item>
  </channel>
</rss>

