<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wildfire new threat signature update in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237296#M67983</link>
    <description>&lt;P&gt;As per Admin guide&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Palo Alto Networks WildFire system also provides signatures for persistent threats that are more evasive and have not yet been discovered by other antivirus solutions. As threats are discovered by WildFire, signatures are quickly created and then integrated into the standard Antivirus signatures that can be downloaded by Threat Prevention subscribers on a daily basis (sub-hourly for WildFire subscribers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does it mean that WF if does not know any Antivirus signature it quickly creates it and when we have 5 mins update with&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WF cloud&amp;nbsp; that new signature comes and becomes part of antivirus profile only.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Need to know when new signature comes from WF it is only for the Antivirus profile?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Oct 2018 15:30:32 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2018-10-26T15:30:32Z</dc:date>
    <item>
      <title>Wildfire new threat signature update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237296#M67983</link>
      <description>&lt;P&gt;As per Admin guide&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Palo Alto Networks WildFire system also provides signatures for persistent threats that are more evasive and have not yet been discovered by other antivirus solutions. As threats are discovered by WildFire, signatures are quickly created and then integrated into the standard Antivirus signatures that can be downloaded by Threat Prevention subscribers on a daily basis (sub-hourly for WildFire subscribers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does it mean that WF if does not know any Antivirus signature it quickly creates it and when we have 5 mins update with&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WF cloud&amp;nbsp; that new signature comes and becomes part of antivirus profile only.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Need to know when new signature comes from WF it is only for the Antivirus profile?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 15:30:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237296#M67983</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-26T15:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire new threat signature update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237328#M67991</link>
      <description>&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If WildFire analyses a file that it has never seen before - if the verdict is deemed as malicious it will create a signature that can be made available to people with a WildFire license within 5 minutes. Otherwise if you don't have a WildFire license, it will be made available within 24/48 hours via a threat content update - provided you have a threat prevention license.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WildFire signatures are enforced via the "WildFire Action" in an antivirus security profile, yes - but as well as the DNS signatures enforced via an antispyware security profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/wildfire/wf_admin/wildfire-overview/wildfire-concepts/wildfire-signatures" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/wildfire/wf_admin/wildfire-overview/wildfire-concepts/wildfire-signatures&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/81/pan-os/pan-os/threat-prevention/threat-signatures" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/81/pan-os/pan-os/threat-prevention/threat-signatures&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 17:47:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237328#M67991</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-26T17:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire new threat signature update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237330#M67992</link>
      <description>&lt;P&gt;Firewall will create hash of file and send it to WF to check if this file has been checked before.&lt;/P&gt;&lt;P&gt;If it has then based on verdict file is permitted through or blocked.&lt;/P&gt;&lt;P&gt;If it has not been checked then file is passed through and copy is sent to WF to be analyzed.&lt;/P&gt;&lt;P&gt;Verdict will come back in 5 mins or less.&lt;/P&gt;&lt;P&gt;Those who don't have WF subscription can upload only PE files to WF (exe, dll etc) and they get rest of WF signatures with next Antivirus and Antispyware update.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 18:12:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237330#M67992</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-26T18:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire new threat signature update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237393#M68009</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Sorry for being a smart aleck &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Firewall will create hash of file and send it to WF to check if this file has been checked before.&lt;/P&gt;&lt;P&gt;If it has then based on verdict file is permitted through or blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The firewall does not allow/block based on a WF verdict, only Traps does. The firewall only blocks based on WF signatures of malware-verdict-files which it receives all few minutes. The hash check is only done to check if the file is unknown and needs to be uploaded to WF.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 21:07:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237393#M68009</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-26T21:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire new threat signature update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237396#M68010</link>
      <description>&lt;P&gt;Traps has capability to hold back execution of unknown file until verdict comes back from WF.&lt;/P&gt;&lt;P&gt;Firewall will pass unknown files through but those that have been already checked by WF and verdict was malicious are blocked.&lt;/P&gt;&lt;P&gt;This check is done based on file hash.&lt;/P&gt;&lt;P&gt;Check Action column on the screenshot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wildfire.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17321i430B473629C09EC1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="wildfire.JPG" alt="wildfire.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 21:20:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237396#M68010</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-26T21:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire new threat signature update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237399#M68011</link>
      <description>&lt;P&gt;In the wildfire log the action is only based on the fact if there is already a WF signature. So for every WF log entry with action block you also have a threat log entry either as virus or wildfire-virus. Thats also the reason why (also in your screenshot) you have malicious files with action allow. These with action allow are the ones where so far isn't a WF signature available.&lt;/P&gt;&lt;P&gt;Another reason why a signature is required is because paloalto firewalls are still stream based, they block the file already when the signature matches a part of the file, at that point the file doesn't have to be fully transfered.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 21:47:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/237399#M68011</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-26T21:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire new threat signature update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/457757#M101842</link>
      <description>&lt;P&gt;HI Luke!&lt;/P&gt;&lt;P&gt;Which functionality is available to firewall users with an active Threat Prevention subscription, but no&lt;BR /&gt;WildFire license?&amp;nbsp;Access to the WildFire API or&amp;nbsp;PE file upload to WildFire?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 09:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-new-threat-signature-update/m-p/457757#M101842</guid>
      <dc:creator>AK74</dc:creator>
      <dc:date>2022-01-10T09:28:08Z</dc:date>
    </item>
  </channel>
</rss>

