Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
About Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.

Discussions

Welcome to the Threat & Vulnerability Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4385 Views
  • 0 replies
  • 0 Likes

DNS Traffic slow/time out after applying Anti Spyware

Hi everyone,We are using PAN OS 9.1.5.Our internal hosts and DNS server are in different PA Zones.We have a policy to allow all hosts to access DNS servers with application "dns".We used strict anti spyware profile on the above mentioned security policy.After applying anti-spyware profile, we see that the DNS queries timeout most of the times an...

High alert with signature

Hello, I'm sending out a message in a bottle — I'm noticing a very high number of false positives on signatures with a high severity level, whether they are Anti-Spyware or Vulnerability Protection signatures. The issue is that the solution doesn't implement a scoring system to determine the relevance of its alerts. I'm wondering if anyone has...

Inquiry About Building and Publishing a Cortex XDR Integration

Hi Team,We have a customer interested in developing a data connector for Cortex XDR, with the intention of making it publicly available via the Cortex XDR Marketplace. Our team will take full ownership of the development process, and we’d appreciate your guidance on best practices, platform limitations, and the overall integration and publishing...

Threat ID: 31671 - SCADA ICCP Unauthorized COTP Connection Established

SCADA, or Supervisory Control and Data Acquisition, systems are critical industrial control systems that monitor and manage sensitive processes. This alert, "Threat ID: 31671 - SCADA ICCP Unauthorized COTP Connection Established," signifies that an unauthorized ICCP (Inter-Control Center Communications Protocol) client has successfully establish...

Packet Buffer Protection (PBP)

We are receiving multiple alerts for Packet Buffer Protection (PBP) being triggered on internal-to-internal and internal-to-external traffic. My understanding is that PBP is primarily intended to protect against DoS attacks, which are typically external-to-internal in nature.Is it expected behavior for PBP to be triggered by internal-to-internal...

User_707 by L0 Member
  • 8668 Views
  • 1 replies
  • 0 Likes

critical control points

Hi everyone, When it comes to securing firewall management systems—those critical control points in any network—what strategies, best practices, or tools have you found most effective? Whether it’s role-based access controls, dedicated management networks, or using tools like SIEMs or NACs, I’d love to hear what’s worked for you. Are there any l...

VLC update - "Virus" alert PA

Hello, I have a question regarding alert in Threat detection - type "virus" Some endpoints were trying to update VLC player, but it detected as "virus" with this threat ID: 706518286. This is file name: mirror.alwyzon.net/videolan/vlc/3.0.21/win64/vlc-3.0.21-win64.exe. After analysis, I found out that VLC auto-update was trying to download late...

Port 5060 Remains Blocked Despite Threat Exemption

Port 5060 is still being blocked even after the security threat (Threat ID 40016) responsible for the block was added to the exemption list. We’ve already applied the threat exemption to the corresponding security policy, and also cleared the session browser for the specific IP address experiencing blocked traffic on port 5060. However, the issu...

Glenyvie by L1 Bithead
  • 7151 Views
  • 2 replies
  • 0 Likes
  • 548 Posts
  • 80 Subscriptions
Top Liked Authors