<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: botnet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153784#M50727</link>
    <description>&lt;P&gt;you can add the botnet report to a scheduled report group so you receive daily or weekly emails containing useful information regarding the overall health of your network&lt;/P&gt;
&lt;P&gt;if you get a report containing botnet behavior you can then investigate the host that was acting suspiciously&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to really avoid botnets from creeping into your network, you need to button down security by also securing the endpoints with something like&lt;A title="Secure the Endpoint" href="https://www.paloaltonetworks.com/products/secure-the-endpoint/traps" target="_blank"&gt; Traps&lt;/A&gt;, adding Global Protect with HIP checks etc.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Apr 2017 07:57:33 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-04-24T07:57:33Z</dc:date>
    <item>
      <title>botnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/152754#M50486</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If someone running a botnet inside local network ,is there a way to &amp;nbsp;get an alert &amp;nbsp;like siem, from reports ,from live stattistics ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;what are the steps to identify these kind of traffic ?&lt;/P&gt;&lt;P&gt;Finally how to block them when threshold reaches &amp;nbsp;?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Apr 2017 20:01:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/152754#M50486</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-04-16T20:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: botnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153025#M50545</link>
      <description>&lt;P&gt;A botnet can be detected using 2 methods:&lt;/P&gt;
&lt;P&gt;-either it's a 'known' botnet (either signatures exist or heuristics engine can pick it up)&amp;nbsp; and any outgoing traffic will be picked up and reported in your threat log, for which there are built in reports and you can create custom scheduled reports&lt;/P&gt;
&lt;P&gt;-if the infection is unknown or is extremely sneaky (dorment/sleeper agents) the botnet report can help pick up infected hosts from 'suspicious' behavior (the botnet report can also be added to a scheduled report group)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="botnet.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="botnet.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 14:11:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153025#M50545</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-04-18T14:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: botnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153032#M50552</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;I just noticed that monitor option is missing from Panorama... is it just moved somewhere or is that not yet available?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 15:40:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153032#M50552</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-04-18T15:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: botnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153046#M50554</link>
      <description>The botnet reports are only available on the firewall</description>
      <pubDate>Tue, 18 Apr 2017 16:10:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153046#M50554</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-04-18T16:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: botnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153048#M50555</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;, I might reach out to our sales people to ask about this as a feature request for a future version of Panorama.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 16:12:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153048#M50555</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-04-18T16:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: botnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153750#M50724</link>
      <description>&lt;P&gt;Thanks reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had botnet &amp;nbsp;in my network , and caused dataplace cpu hog ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;To avoid these kind of situation what we need to&amp;nbsp;do ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2017 14:29:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153750#M50724</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-04-23T14:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: botnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153784#M50727</link>
      <description>&lt;P&gt;you can add the botnet report to a scheduled report group so you receive daily or weekly emails containing useful information regarding the overall health of your network&lt;/P&gt;
&lt;P&gt;if you get a report containing botnet behavior you can then investigate the host that was acting suspiciously&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to really avoid botnets from creeping into your network, you need to button down security by also securing the endpoints with something like&lt;A title="Secure the Endpoint" href="https://www.paloaltonetworks.com/products/secure-the-endpoint/traps" target="_blank"&gt; Traps&lt;/A&gt;, adding Global Protect with HIP checks etc.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 07:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153784#M50727</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-04-24T07:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: botnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153975#M50781</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Let's say a bot sending heavily from the inside network ,How the system statics can help to figure out ?&lt;BR /&gt;Second thing ,Before we noticing the report ,How can we protect bot bringing down the pa?&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 06:22:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153975#M50781</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2017-04-25T06:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: botnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153995#M50782</link>
      <description>&lt;P&gt;ok so if we ignore the 'botnet' for a second: if the traffic being generated by the inside infected hosts is so severe it brings down your firewall, this will show up in the ACC and system dashboard&lt;/P&gt;
&lt;P&gt;To protect the firewall from this you can set up zone protection profiles (here's a video on how to set these up: &lt;A title="video tutorial :  Zone protection profiles" href="https://live.paloaltonetworks.com/t5/Featured-Articles/Zone-protection-profiles/ta-p/70687" target="_blank"&gt;video tutorial : Zone protection profiles&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;once zone protection is set up, you could create a log forwarding profile to send out emails on any critical system event&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log forwarding.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="log forwarding.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A title=" Zone Protection Recommendations" href="https://live.paloaltonetworks.com/t5/Learning-Articles/Zone-Protection-Recommendations/ta-p/55850" target="_blank"&gt; Zone Protection Recommendations&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 08:13:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet/m-p/153995#M50782</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-04-25T08:13:58Z</dc:date>
    </item>
  </channel>
</rss>

