<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: block http download based on the download file hash value in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-http-download-based-on-the-download-file-hash-value/m-p/66628#M39255</link>
    <description>&lt;P&gt;Hi E&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Palo Alto Networks firewall performs stream-based inspection of file transfers, so no proxy functionality is applied, hence no sha or md hash is collected. We can, however, identify files by all kinds of other means. Could there perhaps be any other identifiable markers, watermarks, headers, propietary strings of data in the file? these could be easily added to a custom app or threat profile, or as a data filtering profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 15 Oct 2015 09:31:05 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2015-10-15T09:31:05Z</dc:date>
    <item>
      <title>block http download based on the download file hash value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-http-download-based-on-the-download-file-hash-value/m-p/66584#M39238</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have asked to look for a solution, &amp;nbsp;we want to receive alert based on specific file download via http, we have the file MD5 or SHA1 hash value. &amp;nbsp; Can I do this with a PAN? &amp;nbsp;The filename could change, &amp;nbsp;I don't know the file size but I have the file hash value..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your helps in advanced,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;E&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 15:37:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-http-download-based-on-the-download-file-hash-value/m-p/66584#M39238</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2015-10-14T15:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: block http download based on the download file hash value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-http-download-based-on-the-download-file-hash-value/m-p/66587#M39241</link>
      <description>&lt;P&gt;If you want to block/alert a file with hash value it is not possible.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 16:04:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-http-download-based-on-the-download-file-hash-value/m-p/66587#M39241</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-10-14T16:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: block http download based on the download file hash value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-http-download-based-on-the-download-file-hash-value/m-p/66628#M39255</link>
      <description>&lt;P&gt;Hi E&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Palo Alto Networks firewall performs stream-based inspection of file transfers, so no proxy functionality is applied, hence no sha or md hash is collected. We can, however, identify files by all kinds of other means. Could there perhaps be any other identifiable markers, watermarks, headers, propietary strings of data in the file? these could be easily added to a custom app or threat profile, or as a data filtering profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 09:31:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-http-download-based-on-the-download-file-hash-value/m-p/66628#M39255</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-10-15T09:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: block http download based on the download file hash value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-http-download-based-on-the-download-file-hash-value/m-p/66926#M39376</link>
      <description>&lt;P&gt;Hi...One option is to use WildFire subscription to upload all interesting file to our WildFire cloud for analysis. &amp;nbsp;From its portal you can see all the files and find the file to match your MD5 hash.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 20:47:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-http-download-based-on-the-download-file-hash-value/m-p/66926#M39376</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2015-10-20T20:47:08Z</dc:date>
    </item>
  </channel>
</rss>

