<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wildfire False positivs ... more than usual in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-false-positivs-more-than-usual/m-p/311052#M80525</link>
    <description>&lt;P&gt;Hi community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our environments we start getting more and more fals positivs from wildfire where documents (mainly docx and xlsx) are flaged as malicious without any reason, or at least a reason without details in the WF report. I wonder if you see the same over the past about 7 days?&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2020 12:49:20 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2020-02-13T12:49:20Z</dc:date>
    <item>
      <title>Wildfire False positivs ... more than usual</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-false-positivs-more-than-usual/m-p/311052#M80525</link>
      <description>&lt;P&gt;Hi community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our environments we start getting more and more fals positivs from wildfire where documents (mainly docx and xlsx) are flaged as malicious without any reason, or at least a reason without details in the WF report. I wonder if you see the same over the past about 7 days?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 12:49:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-false-positivs-more-than-usual/m-p/311052#M80525</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-02-13T12:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire False positivs ... more than usual</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-false-positivs-more-than-usual/m-p/311285#M80566</link>
      <description>&lt;P&gt;In the last few days we've been getting a ton of FP's.&amp;nbsp; None of these files are related in any way, but one commonality we did find was Wildfire was keying on these 2 things:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Http request without User-Agent&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2) HTTP GET requests to x.x.x.x&lt;EM&gt;/wpad.dat (x.x.x.x being the same IP every time).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Also, our WF500 appliance is reporting all of these FP's.&amp;nbsp; If we upload the same file to the WF cloud, the files come back as benign.&amp;nbsp; I have a ticket open with support and they have escalated it to engineering.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 19:31:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-false-positivs-more-than-usual/m-p/311285#M80566</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2020-02-14T19:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire False positivs ... more than usual</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-false-positivs-more-than-usual/m-p/311380#M80585</link>
      <description>&lt;P&gt;In my case the FPs are mostly office documents - no matter what extention (.doc, .docx, .xls, .xlsx). With all of them WF shows "started a process from a user folder" but in the report details there is absolutely nothing about that behavior.&lt;/P&gt;&lt;P&gt;I have also a case open which is also already escalet to engineering.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Feb 2020 09:19:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-false-positivs-more-than-usual/m-p/311380#M80585</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-02-16T09:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire False positivs ... more than usual</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-false-positivs-more-than-usual/m-p/311385#M80587</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7542"&gt;@jambulo&lt;/a&gt;&amp;nbsp;did I understand correctly your FPs are &lt;STRONG&gt;only&lt;/STRONG&gt; on your wf500 appliance?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Feb 2020 10:35:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-false-positivs-more-than-usual/m-p/311385#M80587</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-02-16T10:35:09Z</dc:date>
    </item>
  </channel>
</rss>

