What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?

Reply
L2 Linker

What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?

Hi;

 

My understanding is that the PAN OS performs a hash of the file, then checks with Wildfire to see if this file has been seen or not. If it has not been seen, then it performs an AV scan on it to determine if it matches a known signature. If the file does not match any known signature, then and only then it gets sent to Wild-Fire public or private cloud for sandboxing.

 

Please comment if you can.

 

Kindly

Wasfi

Tags (2)
Community Manager

Re: What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?

On-firewall AV scanning is done in transit, so bytes go through the firewall and bytes get scanned

If at any point during the flow a malicious signature is detected the flow is interrupted and the file transfer stopped

Only if the on-device scan does not block a file this way, will we be able to get to the end of the file and collect a hash to check with wildfire if the file has already been uploaded or not.

if the file has not been seen yet, it is uploaded and put in a sandbox


Help the community: Like helpful comments and mark solutions
Reaper out
L7 Applicator

Re: What is applied first Wildfire profile or AV profile? Is the file AV scanned or sandboxed first?

Since march 2018 even files that match an AV signature will be forwarded to wildfire: https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-whats-new/latest-wildfire-cloud-features/wil...

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!