<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block recently registered domains in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/199167#M59051</link>
    <description>&lt;P&gt;We do block the unknown category. A known malicious domain which was registered 8 days prior to the phishing emails being sent through was categorised as computer-and-internet-info.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Feb 2018 22:21:24 GMT</pubDate>
    <dc:creator>ASCIT</dc:creator>
    <dc:date>2018-02-06T22:21:24Z</dc:date>
    <item>
      <title>Block recently registered domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/198705#M58968</link>
      <description>&lt;P&gt;Is anyone successfully blocking domains that have been registered recently (last 30 days)? My testing has shown in the last three days, 380k domains have been registered. My PA-3020 capacity for External Dynamic Lists only supports a total capacity of 50k domains. Does anyone know of a better method to achieve this?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2018 01:46:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/198705#M58968</guid>
      <dc:creator>ASCIT</dc:creator>
      <dc:date>2018-02-04T01:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Block recently registered domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/198906#M59008</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10078"&gt;@ASCIT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;We dont block based on the age of a domain, we only block on categories. Quite a bit of the time, but not always, the newer ones are lumped into the 'Unknow' category and we block that one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would say that not all newly registered domains are 'bad' and can have an impact on the user base.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2018 22:31:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/198906#M59008</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-05T22:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Block recently registered domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/198989#M59019</link>
      <description>&lt;P&gt;Most of the new domains will fall under the 'unknown' category as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt; mentions, until our crawlers pay a visit, or we get submissions/field reports/samples of what the domain is hosting and then it get categorized as one of the regular categories&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so blocking 'unknown' will likely do the job satisfactory&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 10:49:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/198989#M59019</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-06T10:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Block recently registered domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/199167#M59051</link>
      <description>&lt;P&gt;We do block the unknown category. A known malicious domain which was registered 8 days prior to the phishing emails being sent through was categorised as computer-and-internet-info.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 22:21:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/199167#M59051</guid>
      <dc:creator>ASCIT</dc:creator>
      <dc:date>2018-02-06T22:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Block recently registered domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/199179#M59054</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I understand the frustration there. Does your company use a mail filtering tool or service? This is where it should have gotten caught&amp;nbsp;I think since it was delivered via an email?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a few thoughts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 00:00:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/199179#M59054</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-07T00:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Block recently registered domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/199188#M59057</link>
      <description>&lt;P&gt;Thanks for your input. Blocking this traffic at the firewall would be far more effective.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 00:24:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-recently-registered-domains/m-p/199188#M59057</guid>
      <dc:creator>ASCIT</dc:creator>
      <dc:date>2018-02-07T00:24:11Z</dc:date>
    </item>
  </channel>
</rss>

