Custom Signatures

The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Custom Signatures
The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.
About Custom Signatures

Welcome to the Custom Signatures discussion forum. This forum exists as a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance. Please feel free to engage with other community members and Palo Alto Networks staff. Ideas, questions, research, and observations regarding the process of custom signature creation are all actively encouraged.

For an introduction to the forum, please see the sticky!

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to custom signatures. Please use the information from this forum at your own risk and make sure to test and verify any signature and code presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the Custom Signatures Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 509 Views
  • 0 replies
  • 0 Likes

Palo Alto Reponse to CVE-2023-48795

Hi all! I am curious whether  anyone knows if Palo Alto has any made any response to CVE-2023-48795? This vulnerabilities has been out for awhile and other vendors have already provided some types of response however, I am not able to find one from P

...

Custom Application - Exception for AWS

Looking for some help from smart people. 

 

Uploading and Downloading per application to/from AWS is not allowed per our InfoSec team.  We have more and more cloud based web applications coming through now that are using AWS on the backend and that i

...

2025-04-16 16_05_00-Window.png
2025-04-16 16_04_41-Window.png

Welcome to the Custom Signatures Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 509 Views
  • 0 replies
  • 0 Likes

Wildfire

Hello Team,

 

We have an alert in our Splunk for Palo Alto Wildfire with threat name as "Email Link". However checking, see both user and recipients are same for the alert log and don't see any such subjected email in our Email Gateway (Proofpoint).

...

intermediate certificates

Hello everyone,

 

Is there a solution other than manually importing intermediate certificates into the Palo Alto Firewall (PAN-OS10.2.9-h1)?

Since there are weekly a few websites with this problem popping up.

 

I already know the import procedure tha

...

smledv by L1 Bithead
  • 1525 Views
  • 1 replies
  • 0 Likes

Blocking claudebot from scanning sites

Is it possible to create a rule/application (or if there is an existing one) to block certain bots from scanning websites behind the firewall?  I see the claude application, but I'm guessing this is more for outbound requests than for blocking the bo

...

adepinto by L0 Member
  • 2452 Views
  • 1 replies
  • 0 Likes

Zoom phone custom signature thru: ssl-req-chello-sni

Hi everyone!

 

We are currently moving our phone system to zoom, and we had an issue with the zoom application, some of their traffic its categorized as an incomplete causing that some calls hang out, or don't ring, i downloaded the packet capture lo

...

R.Tudon by L1 Bithead
  • 1808 Views
  • 0 replies
  • 0 Likes

Palo Alto Threat Vault AntiVirus Signatures

Hi Community!

 

I wanted to better understand how Palo Alto ties it's detections with its Unique Threat ID to the Wildfire Virus Detections. 

 

For example, we have been receiving a steady amount of alerting for a Virus File and Palo Alto gives us th

...

  • 168 Posts
  • 83 Subscriptions
Labels