Wildfire Verdict benign / Action block

Reply
L1 Bithead

Wildfire Verdict benign / Action block

I'd like to understand how Wildfire works. I have this example where Verdict is benign and action is block. Why?

 

PA1.png

 

PA2.png

L1 Bithead

Re: Wildfire Verdict benign / Action block

Filtering by Session ID I have this logs:

 

PA3.png

L7 Applicator

Re: Wildfire Verdict benign / Action block

@Keny_Schmeling,

What likely happended was the firewall identified the traffic via a signature or local analysis and determined that it was malicious; when it was sent to the wildfire cloud and actually ran in the sandbox environment it was discovered to be benign. Therefore the verdict would report benign, because it is, but the firewall would have blocked the traffic before the file was sent off to be analyzed. 

Now if the hash of the file is seen by your firewall again, it will allow the file as the hash is known to be benign. Likewise, if I attempted to download the same file on my firewall it would also be allowed, because you've already analyzed the file and the hash is known to be benign. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!