<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to test AV Functionality when Eicar is not recognised? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68904#M40087</link>
    <description>&lt;P&gt;Thanks, I will test it.&lt;/P&gt;
&lt;P&gt;Roman&lt;/P&gt;</description>
    <pubDate>Wed, 02 Dec 2015 11:32:57 GMT</pubDate>
    <dc:creator>rkra</dc:creator>
    <dc:date>2015-12-02T11:32:57Z</dc:date>
    <item>
      <title>How to test AV Functionality when Eicar not in signatures?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68860#M40077</link>
      <description>&lt;P&gt;How to test AV Functionality when Eicar is not recognized by the Firewall?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Roman&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 23:02:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68860#M40077</guid>
      <dc:creator>rkra</dc:creator>
      <dc:date>2015-12-01T23:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to test AV Functionality when Eicar is not recognised?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68862#M40078</link>
      <description>&lt;P&gt;Identify what policy allows traffic.&lt;/P&gt;
&lt;P&gt;Do you have antivirus security profile attached to this policy?&lt;/P&gt;
&lt;P&gt;Is Eicar downloaded over web-browsing or inside ssl traffic?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 17:48:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68862#M40078</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-12-01T17:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to test AV Functionality when Eicar is not recognised?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68867#M40080</link>
      <description>&lt;P&gt;Eicar is the only safe way to test AV functionality. The Eicar files are recognized by the firewall's AV, so it should be a valid test for you as long as you are scanning for the traffic (i.e., make sure you have an AV profile for the traffic type, make sure you're decrypting SSL if it's on an SSL page, etc.).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anything else you do can potentially be dangerous to your network. If the firewall is misconfigured and you use a live malware file, you risk compromising your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 18:37:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68867#M40080</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-12-01T18:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to test AV Functionality when Eicar is not recognised?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68872#M40082</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;recognized by the Firewall = not in the signatures in last months, please see here&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Eicar-no-longer-in-AV-signatures/m-p/66700/highlight/true#M39288" target="_self"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Eicar-no-longer-in-AV-signatures/m-p/66700/highlight/true#M39288&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does your firewall find eicar here ? &lt;A href="https://www.etes.de/downloads/eicar-testvirus/" target="_self"&gt;https://www.etes.de/downloads/eicar-testvirus/ &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Roman&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 23:06:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68872#M40082</guid>
      <dc:creator>rkra</dc:creator>
      <dc:date>2015-12-01T23:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to test AV Functionality when Eicar is not recognised?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68895#M40083</link>
      <description>&lt;P&gt;There was a bug in the AV signature update for Eicar a while ago, but it's working fine again now. I'm right now using AV version 1707-2185. Are your AV signatures updated?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go to Monitor -&amp;gt; URL Filtering, and filter out "( referer eq '&lt;A href="http://www.eicar.org/85-0-Download.html'" target="_blank"&gt;http://www.eicar.org/85-0-Download.html'&lt;/A&gt; )". You could perhaps also add "and ( url eq '&lt;A href="http://www.eicar.org/download/eicar.com'" target="_blank"&gt;www.eicar.org/download/eicar.com'&lt;/A&gt; )" if you clicked the first test object on Eicar.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check the column "Rule", to see which rule it hits.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then check the policy, and the correct Rule, to see if you have a working AV profile there. Action "allow" in the profile will most likely not log anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When everything is working, you should be able to click the magnifier for the selected logs in URL filtering, and in there see related logs, and there the Eicar virus.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2015 07:52:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68895#M40083</guid>
      <dc:creator>gtomte</dc:creator>
      <dc:date>2015-12-02T07:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to test AV Functionality when Eicar is not recognised?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68904#M40087</link>
      <description>&lt;P&gt;Thanks, I will test it.&lt;/P&gt;
&lt;P&gt;Roman&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2015 11:32:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-test-av-functionality-when-eicar-not-in-signatures/m-p/68904#M40087</guid>
      <dc:creator>rkra</dc:creator>
      <dc:date>2015-12-02T11:32:57Z</dc:date>
    </item>
  </channel>
</rss>

