<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat False Positives? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234788#M67305</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Looks like this was the emergency update that came out last night:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17098iB21B91E7D0D68053/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I usually&amp;nbsp;set my dynamic updates with a threshold that will allow the updates to bake since they have released bum updates in the past. I understand there are some environments where this is not possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/best-practices-for-content-and-threat-content-updates.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/best-practices-for-content-and-threat-content-updates.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 10 Oct 2018 14:00:56 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-10-10T14:00:56Z</dc:date>
    <item>
      <title>Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234730#M67283</link>
      <description>&lt;P&gt;Our threat logs are full of 'Fallout Exploit Kit Detection' this morning from many of our networks, although no actul issues have been found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fallout.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17094i7D2E2D358B937CA4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fallout.png" alt="fallout.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 12:08:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234730#M67283</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-10-10T12:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234755#M67290</link>
      <description>&lt;P&gt;Same here...I installed 8077 this morning when I get in after reading the email and I'm getting Fallout alerts like crazy. I don't have as many as you, but people just starting coming in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-10-10 08_16_13-Panorama.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17095i3A4F16E37DC6BE9B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-10-10 08_16_13-Panorama.png" alt="2018-10-10 08_16_13-Panorama.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 13:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234755#M67290</guid>
      <dc:creator>bbilut</dc:creator>
      <dc:date>2018-10-10T13:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234767#M67293</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5457"&gt;@bbilut&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84842"&gt;@OGMaverick&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;For the time being I would recommend rolling this back to 8076. The Fallout siganture has actually been around since 8074, but whatever modification PA has done to the signature is a tad to broad at the moment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 13:39:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234767#M67293</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-10-10T13:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234785#M67303</link>
      <description>&lt;P&gt;I'm rolling back to 8076 and I'll report back what happens. I was getting a detection about every minute or multiple per minute with 8077.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: 8076 seems to have stopped the mass amount of alerts.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 14:05:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234785#M67303</guid>
      <dc:creator>bbilut</dc:creator>
      <dc:date>2018-10-10T14:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234788#M67305</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Looks like this was the emergency update that came out last night:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17098iB21B91E7D0D68053/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I usually&amp;nbsp;set my dynamic updates with a threshold that will allow the updates to bake since they have released bum updates in the past. I understand there are some environments where this is not possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/best-practices-for-content-and-threat-content-updates.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/best-practices-for-content-and-threat-content-updates.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 14:00:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234788#M67305</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-10T14:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234793#M67309</link>
      <description>&lt;P&gt;I m rolling back to 8076 - and alers from IPS disappear.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 14:27:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234793#M67309</guid>
      <dc:creator>pkowalewski</dc:creator>
      <dc:date>2018-10-10T14:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234794#M67310</link>
      <description>&lt;P&gt;Yeah, we are also getting a lot of the Threat ID 30650 events.&amp;nbsp; All events seem to include a *.min.js or *.js file name.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 14:32:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234794#M67310</guid>
      <dc:creator>CTW1983</dc:creator>
      <dc:date>2018-10-10T14:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234795#M67311</link>
      <description>&lt;P&gt;I had the same files - *.js&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 14:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234795#M67311</guid>
      <dc:creator>pkowalewski</dc:creator>
      <dc:date>2018-10-10T14:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234796#M67312</link>
      <description>&lt;P&gt;I do the same... I'm usually a week behind because their updates have burnt me in the past several times. This one seemed urgent so I manually updated this morning. I guess that was a mistake.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 14:36:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234796#M67312</guid>
      <dc:creator>bbilut</dc:creator>
      <dc:date>2018-10-10T14:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234797#M67313</link>
      <description>&lt;P&gt;..Palo Alto -&amp;nbsp;not often&amp;nbsp;makes mistakes in signatures... but .... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; it happend...&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 14:47:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234797#M67313</guid>
      <dc:creator>pkowalewski</dc:creator>
      <dc:date>2018-10-10T14:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234798#M67314</link>
      <description>&lt;P&gt;Agreed, no one is perfect. I usually have a 24 hour threshold on any new signatures for app/threat.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 15:00:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234798#M67314</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-10T15:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234818#M67319</link>
      <description>&lt;P&gt;Same here. PaloAlto 5050 with Application and Threat Version 8077-5070.&lt;/P&gt;&lt;P&gt;Many critical threat log entrys with&amp;nbsp;name-of-threatid eq 'Fallout Exploit Kit Detection' as false-positives.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 16:12:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234818#M67319</guid>
      <dc:creator>M.Eberhardt</dc:creator>
      <dc:date>2018-10-10T16:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234819#M67320</link>
      <description>&lt;P&gt;I looked at the js files being flagged. there must be something in them that is a close match. since these are not critial .js files I am leaving the block in place for now. Has anyone reported this to PA yet?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 16:20:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234819#M67320</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-10-10T16:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234822#M67322</link>
      <description>&lt;P&gt;I just opened a case with PA to see what they say. So far it's creating an issue for one website we use, blocking a particular js file from loading and rendering the website inoperable.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 16:39:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234822#M67322</guid>
      <dc:creator>mikebowen</dc:creator>
      <dc:date>2018-10-10T16:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234836#M67324</link>
      <description>&lt;P&gt;FYI,&lt;/P&gt;&lt;P&gt;8078 was just released that is suppose to address the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 17:47:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234836#M67324</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-10-10T17:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234845#M67328</link>
      <description>&lt;P&gt;8078 is working for us.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 19:06:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234845#M67328</guid>
      <dc:creator>JasonLavetan</dc:creator>
      <dc:date>2018-10-10T19:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234862#M67334</link>
      <description>&lt;P&gt;Same here getting pelted with .js alerts&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 20:51:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234862#M67334</guid>
      <dc:creator>SteveRuberti</dc:creator>
      <dc:date>2018-10-10T20:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Threat False Positives?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234885#M67337</link>
      <description>&lt;P&gt;After instalation 8078&amp;nbsp;IPS/IDS -&amp;nbsp;working fine....&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 07:01:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-false-positives/m-p/234885#M67337</guid>
      <dc:creator>pkowalewski</dc:creator>
      <dc:date>2018-10-11T07:01:17Z</dc:date>
    </item>
  </channel>
</rss>

