<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-applied-first-wildfire-profile-or-av-profile-is-the-file/m-p/256917#M72883</link>
    <description>&lt;P&gt;On-firewall AV scanning is done in transit, so bytes go through the firewall and bytes get scanned&lt;/P&gt;
&lt;P&gt;If at any point during the flow a malicious signature is detected the flow is interrupted and the file transfer stopped&lt;/P&gt;
&lt;P&gt;Only if the on-device scan does not block a file this way, will we be able to get to the end of the file and collect a hash to check with wildfire if the file has already been uploaded or not.&lt;/P&gt;
&lt;P&gt;if the file has not been seen yet, it is uploaded and put in a sandbox&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2019 05:29:32 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2019-04-10T05:29:32Z</dc:date>
    <item>
      <title>What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-applied-first-wildfire-profile-or-av-profile-is-the-file/m-p/256878#M72876</link>
      <description>&lt;P&gt;Hi;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My understanding is that the PAN OS performs a hash of the file, then checks with Wildfire to see if this file has been seen or not. If it has not been seen, then it performs an AV scan on it to determine if it matches a known signature. If the file does not match any known signature, then and only then it gets sent to Wild-Fire public or private cloud for sandboxing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please comment if you can.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly&lt;/P&gt;&lt;P&gt;Wasfi&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 03:58:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-applied-first-wildfire-profile-or-av-profile-is-the-file/m-p/256878#M72876</guid>
      <dc:creator>Wasfi.Bounni</dc:creator>
      <dc:date>2019-04-10T03:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-applied-first-wildfire-profile-or-av-profile-is-the-file/m-p/256917#M72883</link>
      <description>&lt;P&gt;On-firewall AV scanning is done in transit, so bytes go through the firewall and bytes get scanned&lt;/P&gt;
&lt;P&gt;If at any point during the flow a malicious signature is detected the flow is interrupted and the file transfer stopped&lt;/P&gt;
&lt;P&gt;Only if the on-device scan does not block a file this way, will we be able to get to the end of the file and collect a hash to check with wildfire if the file has already been uploaded or not.&lt;/P&gt;
&lt;P&gt;if the file has not been seen yet, it is uploaded and put in a sandbox&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 05:29:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-applied-first-wildfire-profile-or-av-profile-is-the-file/m-p/256917#M72883</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-04-10T05:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-applied-first-wildfire-profile-or-av-profile-is-the-file/m-p/256922#M72886</link>
      <description>&lt;P&gt;Since march 2018 even files that match an AV signature will be forwarded to wildfire: &lt;A href="https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-whats-new/latest-wildfire-cloud-features/wildfire-analysis-of-blocked-files.html#&amp;nbsp;" target="_blank"&gt;https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-whats-new/latest-wildfire-cloud-features/wildfire-analysis-of-blocked-files.html#&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 06:00:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-applied-first-wildfire-profile-or-av-profile-is-the-file/m-p/256922#M72886</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-10T06:00:56Z</dc:date>
    </item>
  </channel>
</rss>

