<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wildfire categorizing as cat=THREAT but not sure why? How to update FPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-categorizing-as-cat-threat-but-not-sure-why-how-to/m-p/357263#M87748</link>
    <description>&lt;P&gt;The way I've been doing it is via the WildFire page at&amp;nbsp;&lt;A href="https://wildfire.paloaltonetworks.com/" target="_blank"&gt;https://wildfire.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to the Reports page and find the entry (if any). Click on the report icon on the left column, scroll to the bottom of the page and report an incorrect verdict. This page only shows what your firewall has uploaded to WildFire, so if another PAN customer was patient zero, you won't see it in here. If you don't see it listed but still want to report it as a false positive, you'll need to upload the file in question on the Upload Sample page. Once the upload is complete, go back to the reports page and you'll see it at the top of the list. You'll then be able to report the incorrect verdict.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have your firewall configured to send you the WildFire report PDF to you via e-mail, you can do the same report incorrect verdict via that PDF as well.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2020 20:26:16 GMT</pubDate>
    <dc:creator>kalakai</dc:creator>
    <dc:date>2020-10-19T20:26:16Z</dc:date>
    <item>
      <title>Wildfire categorizing as cat=THREAT but not sure why? How to update FPs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-categorizing-as-cat-threat-but-not-sure-why-how-to/m-p/357234#M87743</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Apologies in advance if this has been asked, but this is my first post re: Wildfire.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We receive e-mail alerts via our SIEM when something is categorized as malicious from our PA device, but I noticed that all that is listed within the payload that tells me why it was categorized as a threat is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"cat=THREAT"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As well as the hash which has no matches in VirusTotal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can tell by the sending e-mail and recipient that this is a false positive (as well as the subject line) so how can I ensure that wildfire learns this is not a threat? There is not much I can go off of in terms of the payload. I would just like to fine tune our alerts in PA/wildfire.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 18:42:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-categorizing-as-cat-threat-but-not-sure-why-how-to/m-p/357234#M87743</guid>
      <dc:creator>EdwardShim</dc:creator>
      <dc:date>2020-10-19T18:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Wildfire categorizing as cat=THREAT but not sure why? How to update FPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-categorizing-as-cat-threat-but-not-sure-why-how-to/m-p/357263#M87748</link>
      <description>&lt;P&gt;The way I've been doing it is via the WildFire page at&amp;nbsp;&lt;A href="https://wildfire.paloaltonetworks.com/" target="_blank"&gt;https://wildfire.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to the Reports page and find the entry (if any). Click on the report icon on the left column, scroll to the bottom of the page and report an incorrect verdict. This page only shows what your firewall has uploaded to WildFire, so if another PAN customer was patient zero, you won't see it in here. If you don't see it listed but still want to report it as a false positive, you'll need to upload the file in question on the Upload Sample page. Once the upload is complete, go back to the reports page and you'll see it at the top of the list. You'll then be able to report the incorrect verdict.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have your firewall configured to send you the WildFire report PDF to you via e-mail, you can do the same report incorrect verdict via that PDF as well.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 20:26:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-categorizing-as-cat-threat-but-not-sure-why-how-to/m-p/357263#M87748</guid>
      <dc:creator>kalakai</dc:creator>
      <dc:date>2020-10-19T20:26:16Z</dc:date>
    </item>
  </channel>
</rss>

