<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire verdict malicious and action alert in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-malicious-and-action-alert/m-p/118024#M45603</link>
    <description>&lt;P&gt;Hi Jordi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is possible if the file has not been seen by wildfire before: if a file is known to be malware, the antivirus profile action will be applied, so if you configured the profile to block, it will block the file. this will be logged in the threat log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if the file is not known yet, it will need to be sent to wildfire for analysis first. because the file transfer needs to complete for the entire file to be uploaded to the cloud, the session will not get blocked. once the upload is completed, a log is created to indicate the file was uploaded. since the log is to indicate an upload to the cloud, the action in the wildfire submission logs will always be alert&lt;/P&gt;</description>
    <pubDate>Thu, 06 Oct 2016 07:10:18 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-10-06T07:10:18Z</dc:date>
    <item>
      <title>Wildfire verdict malicious and action alert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-malicious-and-action-alert/m-p/117845#M45600</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have seen in Wildfire Submissions that all files identified as Malicious and Grayware the action is Alert. The Wildfire Profile is configures to forward to public cloud and Antivirus profile has reset-both in Wilfdire Action tab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a normal work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the Wildfire Submission&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5801iDD796723766D5C94/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;Thanks a lot,&lt;/P&gt;&lt;P&gt;Jordi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 15:37:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-malicious-and-action-alert/m-p/117845#M45600</guid>
      <dc:creator>COMIP</dc:creator>
      <dc:date>2016-10-05T15:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire verdict malicious and action alert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-malicious-and-action-alert/m-p/118024#M45603</link>
      <description>&lt;P&gt;Hi Jordi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is possible if the file has not been seen by wildfire before: if a file is known to be malware, the antivirus profile action will be applied, so if you configured the profile to block, it will block the file. this will be logged in the threat log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if the file is not known yet, it will need to be sent to wildfire for analysis first. because the file transfer needs to complete for the entire file to be uploaded to the cloud, the session will not get blocked. once the upload is completed, a log is created to indicate the file was uploaded. since the log is to indicate an upload to the cloud, the action in the wildfire submission logs will always be alert&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2016 07:10:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-malicious-and-action-alert/m-p/118024#M45603</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-10-06T07:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire verdict malicious and action alert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-malicious-and-action-alert/m-p/118127#M45609</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that our wildfire is not working correctly or is bad configured. Is rare that all actions are alert, there are no one block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have do wildfire test with &lt;A title="http://wildfire.paloaltonetworks.com/publicapi/test/pe" href="http://wildfire.paloaltonetworks.com/publicapi/test/pe" target="_blank" rel="nofollow noopener noreferrer"&gt;http://wildfire.paloaltonetworks.com/publicapi/test/pe&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;With the first download Paloalto identify the file as malware and action is block&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WF first download.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5806iDB2675FEAE68A176/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="WF first download.png" alt="WF first download.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After 30 minutes and new wildfire updates I put the same file to ftp and the result continues malware and action alert&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WF to ftp.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5807i713ACF98DDC96FE9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="WF to ftp.png" alt="WF to ftp.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wildfire profile is configured as forward to public-cloud and Antivirus profile is configured as block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jordi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2016 10:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-malicious-and-action-alert/m-p/118127#M45609</guid>
      <dc:creator>COMIP</dc:creator>
      <dc:date>2016-10-06T10:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire verdict malicious and action alert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-malicious-and-action-alert/m-p/118143#M45611</link>
      <description>&lt;P&gt;Hi Jordi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the test PE file will only allow you to verify if uploading and cloud analysis works for your deployment, it is not blocked as we don't generate signatures for the test file&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also, in the wildfire submission log, action will always be alert (as it simply logs the upload), traffic and more specifically threat log will give you the action that was taken on the session itself (block)&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2016 11:06:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-verdict-malicious-and-action-alert/m-p/118143#M45611</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-10-06T11:06:27Z</dc:date>
    </item>
  </channel>
</rss>

