<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Malicious file not getting blocked in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/malicious-file-not-getting-blocked/m-p/173418#M54584</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Something to keep in mind as well is that most documents that I see from SMTP has to be sent to wildfire and the verdict has to come after it's been analyzed; so dropping it on the fly doesn't really work that well and might not be advisable depending on your companies tolerance to any false positive emails being unrecoverable.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Aug 2017 14:04:55 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-08-28T14:04:55Z</dc:date>
    <item>
      <title>Malicious file not getting blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malicious-file-not-getting-blocked/m-p/173401#M54581</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;An email attachment has been classified by Wildfire as malicious. However, it was not blocked and just an alert was logged.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Below are two&amp;nbsp;screenshots from the Wildfire submission and threat logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;Any idea why has the Vulnerability Protection classified this threat as medium even though WildFire classified this file as malicious? How to make sure it is blocked?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10937i13674A9ADD072D16/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Log.jpg" alt="Log.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Wildfire.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10938iAE40FA26F89F3EF2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Wildfire.jpg" alt="Wildfire.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 09:56:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malicious-file-not-getting-blocked/m-p/173401#M54581</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-08-28T09:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Malicious file not getting blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malicious-file-not-getting-blocked/m-p/173404#M54583</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm guessing you don't have your device&amp;nbsp;configured to drop this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The default WildFire action for the SMTP decoder is&amp;nbsp;alert :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="default action for smtp decoder is alert" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10939iA9AB66C6D696F39B/image-size/large?v=v2&amp;amp;px=999" role="button" title="2017-08-28_12-15-57.jpg" alt="default action for smtp decoder is alert" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;default action for smtp decoder is alert&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, this article might be useful :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Enable-WildFire-to-Block-File-with-malicious-Verdict/ta-p/54376" target="_blank"&gt;How-to-Enable-WildFire-to-Block-File-with-malicious-Verdict&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 10:18:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malicious-file-not-getting-blocked/m-p/173404#M54583</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-08-28T10:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: Malicious file not getting blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/malicious-file-not-getting-blocked/m-p/173418#M54584</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Something to keep in mind as well is that most documents that I see from SMTP has to be sent to wildfire and the verdict has to come after it's been analyzed; so dropping it on the fly doesn't really work that well and might not be advisable depending on your companies tolerance to any false positive emails being unrecoverable.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2017 14:04:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/malicious-file-not-getting-blocked/m-p/173418#M54584</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-28T14:04:55Z</dc:date>
    </item>
  </channel>
</rss>

