<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to block malware getting executed?. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306529#M79629</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Unfortunately this is a complicated answer. The best defense is a multi-layered one. While the PAN is a great platform, it should not be the only defense you have. I always tell folks the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use a secure DNS provider such as OpenDNS, TitanHQ, or Quad9. Even PAN has one now.&lt;/LI&gt;&lt;LI&gt;Secure your boarder, i.e. use a PAN and configure all options, App/Threat, Wildfire/ etc.&lt;UL&gt;&lt;LI&gt;Block all non-essential inbount traffic with Layer7&lt;/LI&gt;&lt;LI&gt;Block all outbound non-esesntial traffic with layer7, URL filtering, ssl decryption, etc.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;on the endpoint:&lt;UL&gt;&lt;LI&gt;Use an next gen AV product, i.e. Traps, FireAmp, etc.&lt;/LI&gt;&lt;LI&gt;Get logging and telemetry from the endpoint, FireAMP has this built it, CB Response is another&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Segment your network, zero-trust is a great option.&lt;/LI&gt;&lt;LI&gt;Get Netflow data&lt;/LI&gt;&lt;LI&gt;Use a SIEM to bring all logs together for analysis&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;ELK has been doing great work in this area, they have a SIEM module now.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;TEST!&amp;nbsp;&lt;UL&gt;&lt;LI&gt;make sure you are getting logging/blocking, etc!&lt;/LI&gt;&lt;LI&gt;Atomic RedTeam&lt;/LI&gt;&lt;LI&gt;MonkeyIsland&lt;/LI&gt;&lt;LI&gt;Nessus&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Remember that security is not a destination, its a circular journey&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm sure I might have missed some areas, so I'm interested in what others post as well.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jan 2020 17:21:46 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2020-01-13T17:21:46Z</dc:date>
    <item>
      <title>How to block malware getting executed?.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306474#M79621</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui_content_title ui_content_title--default ui_content_title--large"&gt;&lt;SPAN class="ui_qtext_rendered_qtext"&gt;I would like to block malware files. On my gateway firewall, what filetypes should I block? . If I block only exe/DLL files getting dowloaded, will it help to avoid final malware getting executed ?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN&gt;&lt;SPAN class="ui_content_title ui_content_title--default ui_content_title--large"&gt;&lt;SPAN class="ui_qtext_rendered_qtext"&gt;What I would like to understand is, even if I allow communication with Command and Control (C2) servers, if I block executable/dll files, will it really block malware ultimate purpose?.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="ui_content_title ui_content_title--default ui_content_title--large"&gt;&lt;SPAN class="ui_qtext_rendered_qtext"&gt;Final payload will be only executable like exe/dll?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 12:30:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306474#M79621</guid>
      <dc:creator>Raja3000</dc:creator>
      <dc:date>2020-01-13T12:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to block malware getting executed?.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306529#M79629</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Unfortunately this is a complicated answer. The best defense is a multi-layered one. While the PAN is a great platform, it should not be the only defense you have. I always tell folks the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use a secure DNS provider such as OpenDNS, TitanHQ, or Quad9. Even PAN has one now.&lt;/LI&gt;&lt;LI&gt;Secure your boarder, i.e. use a PAN and configure all options, App/Threat, Wildfire/ etc.&lt;UL&gt;&lt;LI&gt;Block all non-essential inbount traffic with Layer7&lt;/LI&gt;&lt;LI&gt;Block all outbound non-esesntial traffic with layer7, URL filtering, ssl decryption, etc.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;on the endpoint:&lt;UL&gt;&lt;LI&gt;Use an next gen AV product, i.e. Traps, FireAmp, etc.&lt;/LI&gt;&lt;LI&gt;Get logging and telemetry from the endpoint, FireAMP has this built it, CB Response is another&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Segment your network, zero-trust is a great option.&lt;/LI&gt;&lt;LI&gt;Get Netflow data&lt;/LI&gt;&lt;LI&gt;Use a SIEM to bring all logs together for analysis&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;ELK has been doing great work in this area, they have a SIEM module now.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;TEST!&amp;nbsp;&lt;UL&gt;&lt;LI&gt;make sure you are getting logging/blocking, etc!&lt;/LI&gt;&lt;LI&gt;Atomic RedTeam&lt;/LI&gt;&lt;LI&gt;MonkeyIsland&lt;/LI&gt;&lt;LI&gt;Nessus&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Remember that security is not a destination, its a circular journey&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm sure I might have missed some areas, so I'm interested in what others post as well.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 17:21:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306529#M79629</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-01-13T17:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to block malware getting executed?.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306535#M79630</link>
      <description>&lt;P&gt;Also configure the DNS sinkhole under the Anti spyware profile.&lt;/P&gt;&lt;P&gt;Rest mostly Okta covered.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 18:08:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306535#M79630</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-13T18:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to block malware getting executed?.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306536#M79631</link>
      <description>&lt;P&gt;There are also applications such as CB Protect that white list what can be run/executed on a work station. That way if its not on the white list, it wont execute.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 18:20:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306536#M79631</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-01-13T18:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to block malware getting executed?.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306608#M79645</link>
      <description>&lt;P&gt;To elaborate on the above consider this scenario.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your end user downloads a seemingly malignant file that the PA has no signature for [yet].&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12 hours later that malignant file is found to have malicious payload and PA create a signature for it. So do Sophos, MacAfee, etc etc..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;13 hours later it the file activates on your network. You don't have AV/Malware protection on the endpoints.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;14 hours later your packing your desk.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So&amp;nbsp; as OtK points out, it's a multi layer approach. It's always best to block as close to "SOURCE" as possible, but there needs to be the extra layers and indeed different methods of detection, selecting products from differing vendors who may get an update to you quicker than&amp;nbsp; one of your others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 09:22:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306608#M79645</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-01-14T09:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to block malware getting executed?.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306822#M79694</link>
      <description>&lt;P&gt;Thanks OtakarKlier&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 16:25:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-malware-getting-executed/m-p/306822#M79694</guid>
      <dc:creator>Raja3000</dc:creator>
      <dc:date>2020-01-15T16:25:30Z</dc:date>
    </item>
  </channel>
</rss>

