<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Virus: use of the packet capture in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/virus-use-of-the-packet-capture/m-p/10222#M7505</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I wanted to know what you usually do when you see a Virus detected on the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp; How do you check that it is not a false positive?&lt;/P&gt;&lt;P&gt;&amp;nbsp; Do you use the packet capture in the case of a virus?&lt;/P&gt;&lt;P&gt;&amp;nbsp; Does the name/id of the Virus help you to find more details on the web?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Dec 2010 00:00:01 GMT</pubDate>
    <dc:creator>LoopSupport</dc:creator>
    <dc:date>2010-12-09T00:00:01Z</dc:date>
    <item>
      <title>Virus: use of the packet capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virus-use-of-the-packet-capture/m-p/10222#M7505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I wanted to know what you usually do when you see a Virus detected on the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp; How do you check that it is not a false positive?&lt;/P&gt;&lt;P&gt;&amp;nbsp; Do you use the packet capture in the case of a virus?&lt;/P&gt;&lt;P&gt;&amp;nbsp; Does the name/id of the Virus help you to find more details on the web?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 00:00:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virus-use-of-the-packet-capture/m-p/10222#M7505</guid>
      <dc:creator>LoopSupport</dc:creator>
      <dc:date>2010-12-09T00:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Virus: use of the packet capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virus-use-of-the-packet-capture/m-p/10223#M7506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To check if it is false positive, you will need to open a case with support and provide them the virus/threat information and also if possible a sample pcap.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 16:37:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virus-use-of-the-packet-capture/m-p/10223#M7506</guid>
      <dc:creator>odaos</dc:creator>
      <dc:date>2010-12-10T16:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Virus: use of the packet capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virus-use-of-the-packet-capture/m-p/10224#M7507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi LoopSupport,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use pcaps in the case of a virus, and the name and threat ID may help you find more detailed data generally on the internet.&amp;nbsp; There are plenty of sites out there that have research data on viruses.&amp;nbsp; The threat ID's may not always match though, and there are quite often variants of different viruses, so it may or may not help you with internet research in the end.&amp;nbsp; As far as false positives, viruses are much more rare as false positives.&amp;nbsp; It's not impossible, but it's far more rare than say, IPS signature false positives.&amp;nbsp; If you're suspicious of a false positive virus detection, the PAN support team can help here.&amp;nbsp; The PAN threat team has been presented cases in the past where a customer suspected a false positive, and in the end it turned out to be a true virus.&amp;nbsp; This was determined by doing packet captures of the anomalous behavior and examination by the PAN threat team.&amp;nbsp; Also don't forget that if you do come across a false positive, you always have the ability to create exceptions in your antivirus profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 07:11:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virus-use-of-the-packet-capture/m-p/10224#M7507</guid>
      <dc:creator>spolo</dc:creator>
      <dc:date>2011-02-03T07:11:53Z</dc:date>
    </item>
  </channel>
</rss>

