<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpenPhish Feed False Positives 10/07/17 Around 04:00 EDT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/openphish-feed-false-positives-10-07-17-around-04-00-edt/m-p/180892#M99353</link>
    <description>&lt;P&gt;I do not, no.&amp;nbsp; I use the autofocus hosted minemeld so it's not really something we ever considered doing.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2017 17:16:56 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2017-10-09T17:16:56Z</dc:date>
    <item>
      <title>OpenPhish Feed False Positives 10/07/17 Around 04:00 EDT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openphish-feed-false-positives-10-07-17-around-04-00-edt/m-p/180842#M99351</link>
      <description>&lt;P&gt;We have a URL EDL setup using the OpenPhish miner that comes with Minemeld&amp;nbsp; (openphish.feed miner) that a deny rule is matching against.&amp;nbsp; We have never had any issues with it blocking legitimate URL's but a few days ago the deny rule that matches against the OpenPhish EDL started blocking legitimate sites such as &lt;A href="http://www.youtube.com" target="_blank"&gt;www.youtube.com&lt;/A&gt;, &lt;A href="http://www.dell.com" target="_blank"&gt;www.dell.com&lt;/A&gt;, &lt;A href="http://www.oxford.com" target="_blank"&gt;www.oxford.com&lt;/A&gt; and many more.&amp;nbsp; This started occurring after our FW refreshed the EDL at 04:00 EDT on 10/07/2017.&amp;nbsp; The EDL then did it's next scheduled refresh at 05:00 EDT on 10/07/2017 and the legitimate URL's that were getting blocked were being allowed through.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately it looks like I can only search back to late in the day on 10/08 in the node logs so I can't see what URL's were added prior to the 04:00 refresh on 10/07.&amp;nbsp; Im curious if anyone else on here who happens to use the openphish.feed miner experienced the same?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 15:17:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openphish-feed-false-positives-10-07-17-around-04-00-edt/m-p/180842#M99351</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-10-09T15:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: OpenPhish Feed False Positives 10/07/17 Around 04:00 EDT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openphish-feed-false-positives-10-07-17-around-04-00-edt/m-p/180875#M99352</link>
      <description>&lt;P&gt;Do you have a logstash sending the indicator additions and removals over to your siem?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 16:59:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openphish-feed-false-positives-10-07-17-around-04-00-edt/m-p/180875#M99352</guid>
      <dc:creator>chirss</dc:creator>
      <dc:date>2017-10-09T16:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: OpenPhish Feed False Positives 10/07/17 Around 04:00 EDT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openphish-feed-false-positives-10-07-17-around-04-00-edt/m-p/180892#M99353</link>
      <description>&lt;P&gt;I do not, no.&amp;nbsp; I use the autofocus hosted minemeld so it's not really something we ever considered doing.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 17:16:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openphish-feed-false-positives-10-07-17-around-04-00-edt/m-p/180892#M99353</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-10-09T17:16:56Z</dc:date>
    </item>
  </channel>
</rss>

