<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat signatures requiring ssl decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/107645#M44898</link>
    <description>&lt;P&gt;Not a single signature will trigger on encrypted traffic. If you want to check encrypted traffic for threats, you MUST decrypt it.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Aug 2016 07:05:18 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2016-08-26T07:05:18Z</dc:date>
    <item>
      <title>Threat signatures requiring ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/107463#M44885</link>
      <description>&lt;P&gt;Is there a way to determine if a threat signature requires ssl decrypt in order to provide protection. I undertsnad this could have at least three posibilities being fully required, partially required, and not required. Using signature 14616 in content version 608 as an example, I cannot determine if I will ever see hits on this threat ID if I don't leverage ssl decrypt on the session.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 19:57:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/107463#M44885</guid>
      <dc:creator>Lepton</dc:creator>
      <dc:date>2016-08-25T19:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Threat signatures requiring ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/107476#M44886</link>
      <description>&lt;P&gt;Non of the threat id's *require* that your traffic is decrypted, if it detects the signature then it will trigger. If it can't detect the signature because of the encryption then it will not trigger.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 20:39:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/107476#M44886</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-08-25T20:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Threat signatures requiring ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/107645#M44898</link>
      <description>&lt;P&gt;Not a single signature will trigger on encrypted traffic. If you want to check encrypted traffic for threats, you MUST decrypt it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 07:05:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/107645#M44898</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-08-26T07:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Threat signatures requiring ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/107798#M44914</link>
      <description>&lt;P&gt;santonic,&lt;/P&gt;&lt;P&gt;There is actually quite a few threat signatures that trigger based on packet header information&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 15:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/107798#M44914</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-08-26T15:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Threat signatures requiring ssl decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/108122#M44931</link>
      <description>&lt;P&gt;Yeah, signatures which check protocol compliance can still work.&lt;/P&gt;&lt;P&gt;But a short answer would be: if you want to check an encrypted session for possible threats, you have to decrypt it.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 06:59:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-signatures-requiring-ssl-decryption/m-p/108122#M44931</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-08-29T06:59:55Z</dc:date>
    </item>
  </channel>
</rss>

