<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traps local analysis behavior in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178504#M55542</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9102"&gt;@soporteseguridad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you verify that the effected users had actually already tried to launch these executables prior to being unable to reach the ESM? If they hadn't then this kind of makes sense and you should investigate the 'ESM Unreachable' options available within the WildFire policies tab.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the agents didn't already lookup the verdict for that file and have it within their cache, the file would have simply done local analysis and took any action that it's told to take. With the ESM not being reachable the agent doesn't have any idea that you have 'whitelisted' these executables unless the verdict already exists in the agent cache. I'm also not positive if this cache is maintained during a restart.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Sep 2017 12:47:01 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-09-25T12:47:01Z</dc:date>
    <item>
      <title>Traps local analysis behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178474#M55535</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last week we had a problem with TRAPS. We have ESM in the cloud, and we have traps agents in diferente sites.&amp;nbsp;One of these sites had a problem with the internet, so traps could not contact the cloud. The case is that we have executables that traps detect as viruses and that we allowed, so once that agent could not contact with the cloud eliminated these executables.&amp;nbsp;It seems like local analysis it detects the virus and it eliminates the executables.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How local analysis works? I thought that local analysis kept signatures in case it could not contact the cloud&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a a lot&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 09:46:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178474#M55535</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-09-25T09:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Traps local analysis behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178504#M55542</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9102"&gt;@soporteseguridad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you verify that the effected users had actually already tried to launch these executables prior to being unable to reach the ESM? If they hadn't then this kind of makes sense and you should investigate the 'ESM Unreachable' options available within the WildFire policies tab.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the agents didn't already lookup the verdict for that file and have it within their cache, the file would have simply done local analysis and took any action that it's told to take. With the ESM not being reachable the agent doesn't have any idea that you have 'whitelisted' these executables unless the verdict already exists in the agent cache. I'm also not positive if this cache is maintained during a restart.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 12:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178504#M55542</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-25T12:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Traps local analysis behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178517#M55546</link>
      <description>&lt;P&gt;Yes, i confirm that&amp;nbsp;a&lt;SPAN&gt;ffected users had launched these executables before. i attach a screenshot with Widlfire tab&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capturatraps.JPG.png" style="width: 393px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11469iCB308F5BC4AFF1DE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capturatraps.JPG.png" alt="Capturatraps.JPG.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;any recommendation?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 13:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178517#M55546</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-09-25T13:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Traps local analysis behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178571#M55553</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9102"&gt;@soporteseguridad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What version of Traps are you running?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The setting that I'm talking about is actually located under the Policies tab, under the Malware section click on WildFire. The listed policies there if you click on edit on one of them it should show 'Unknown Verdict Configuration' with two options for 'WildFire Verdict is Unavailable' along with 'ESM Unreachable' like the picture below. What exactly does it show there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it quarantined the file I'm guessing that your 'Quarantine Prevented Files' option is currently set to On.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11481i536C73A5A7929AD2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 18:07:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178571#M55553</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-25T18:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Traps local analysis behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178709#M55579</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;version is 4.0.4. These are the screenshots:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11497i346171385CE4270E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Captura1.png" alt="Captura1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11496i258797F507394871/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Captura2.png" alt="Captura2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks a lot for your help&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2017 13:30:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178709#M55579</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-09-26T13:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Traps local analysis behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178785#M55589</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9102"&gt;@soporteseguridad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So this is what I think happened.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file wasn't in the agent cache for whatever reason; either it hadn't been opened before, the computer was restarted and the cache cleared, or the cache cleared because the user had opened enough files that the cache removed the existing verdict override cache entry to make room for additional cache information. Without knowing how long the outage is and how many files were scanned that's almost impossible to know for sure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have local analysis turned on for unknown files which in my mind is 'good' but you also have unreachable options set to allow unknown files. As soon as local analysis kicks in and classifies something, the file is no longer unknown. The file is known with whatever verdict the local analysis engine gives it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really I think it is a combination of things. The cache likely got cleared or overwritten due to one of the reasons above, and the local analysis paired with the unreachable options means that, to the best of my knowledge, you are never actually hitting those options. The file doesn't stay in an unknown state after local analysis and therefore it's following whatever the local analysis says to do with the file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2017 18:18:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178785#M55589</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-26T18:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Traps local analysis behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178866#M55602</link>
      <description>&lt;P&gt;Perfect. Thanks a lot for your findings. Any advice in order to prevent this another time???? This problem occurred to one whole site (site with internet outage), not just one device?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 06:40:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178866#M55602</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-09-27T06:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Traps local analysis behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178955#M55611</link>
      <description>&lt;P&gt;If this is just a set of executables I would include them in the Executable Files Whitelist. This makes it so that the agent itself knows that you've whitelisted the executable and you won't have to worry about the file getting a malicious verdict. If you simply have a verdict override and you lose the connection to the ESM you are relying on the cache entry being present on the agent; if you switch any verdict override for specified executables to this whitelist then the agent doesn't have to rely on connection to the ESM or having the cache entry.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 13:36:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traps-local-analysis-behavior/m-p/178955#M55611</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-27T13:36:45Z</dc:date>
    </item>
  </channel>
</rss>

