Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
About Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.

Discussions

Welcome to the Threat & Vulnerability Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by • Community Team Member
  • 4412 Views
  • 0 replies
  • 0 Likes

Resolved! Hotmail session end Reason "threat"

im trying to allow hotmail. i have created a policy to allow hotmail. when going to the web site "mail.live.com" action is "allowed" however the session is ended because "threat" i cant quite find why and/or where hotmail application is being catagorized as a threat. any help? thanks

HOTMAIL.png
wrollins by • L1 Bithead
  • 12677 Views
  • 4 replies
  • 0 Likes

How to test DNS Security Properly?

In reading up on DNS Security I found that URL's provided for testing in the following document, Enabling DNS Security, do not accurately ensure DNS Security feature license is installed and configured. A very accurate indicator of this is that all of those URL's are adequately blocked on a firewall running PAN-OS 8.1.x due to the PAN-DB URL fil...

bspilde by • L4 Transporter
  • 25842 Views
  • 1 replies
  • 1 Likes

DNS logs

Is there a way to view and/or log dns queries and responses (outside of anti-spyware rules)? The passive DNS telemetry configuration seems to do what we want but those fqdn to IP mappings are sent to Palo and it doesn't appear that we can view what fqdns resolve to what IPs in the logs. This doesn't appear to be a feature in the dns proxy object...

mpochan by • L0 Member
  • 13675 Views
  • 2 replies
  • 1 Likes

Credential Phishing Protection troubleshooting

hey community - tearing my hair out here...I've set up a RoDC in my environment and added a test group to the allowed password replication group. I've configured the user and credential agents on the RoDC and they say connected to my firewall, and also successfully connect to the other dcs. I can see my user to ip mapping for my test account....

Community or News Group that has taken Snort signatures and converted them to PaloAlto

This is a very easy question for everybody. A lot of people have most likely created custom signatures from Snort or otherwise to apply to a PaloAlto firewall. Does anyone know of a news group or community in which those signatures have been converted and that you can download free of charge? Also, does anyone know of a list that (to the best...

ScottF by • L1 Bithead
  • 4905 Views
  • 1 replies
  • 0 Likes
  • 548 Posts
  • 80 Subscriptions