Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
About Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.

Discussions

Welcome to the Threat & Vulnerability Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4391 Views
  • 0 replies
  • 0 Likes

Changing Severity Alerts for Specific Vulnerability Severity

One of the logging capabilities allows us to provide an email for certain severity alerts. We are getting innodated with alerts coming in from the baddies on the internet for certain types of alerts. For instance, there is the "Netis/Netcore Router Default Credential Remote Code Execution Vulnerability(39587)" and that is a high severity. Sin...

THREAT false positives on MS software when using Global Protect.

I'm seeing what look slike a lot of false positives when using global protect. For example, Microsoft's Logon.exe excutable and any MS Endpoint patchesAn example isAM_Engine_Patch_1.1.15400.4.exeSHA-256 Hash: 74f9dc35fc9f5ab02e46843e8ccf569478961ea58dc2655690516199c1eab928which PAN-OS 8.0.7 is flagging as Virus/Win32.WGeneric.tphtk(214705593) I ...

NormCook by L0 Member
  • 6353 Views
  • 1 replies
  • 0 Likes

Issue Content release 8061-4973 on PAN-OS 8.1

Hi all, We have experienced big issues after content release 8061-4973 was installed on our 3250 with PAN-OS 8.1.3: - Threat id 40736 was suddenly blocking a lot of letigimate http(s) traffic.- Radius authentication worked randomly, but 95% of the time NOT.- A download from a Symfony server waits 1 minute before the download starts. After rollin...

Resolved! Block grayware files?

We have recently had a few grayware alerts come through and i was wondering is there anyway files marked as grayware in WIldfile could be blocked the same as they are for malicious files? Thanks

CRDF18 by L2 Linker
  • 10589 Views
  • 5 replies
  • 0 Likes

Resolved! Default Action for SQL Injection Attacks

Following a sudden spike in SQLMap threats, I was looking at the default action for SQL injection threats and I noticed that it is is only an "alert" which seems odd for that kind of attack. Has anyone looked deeper into this and/or changed the action and is there a reason for this not being a reset/drop action?

djr by L4 Transporter
  • 25211 Views
  • 6 replies
  • 0 Likes

Cisco Umbrella/OpenDNS queries now being flagged as threat 18003

We use Cisco Umbreall/OpenDNS for secure DNS and web protection. Cisco Umbrella setup guide says that they use DNSCrypt for secure DNS queries. This setup has worked flawless for years until about two weeks ago,. We began getting alerts that the two IP address from OpenDNS (Cisco Umbrella) are now being flagged periodically as threat 18003 DNS ...

Sinkhole dns-wildfire

How does the dns-wildfire threat category work? I've seen a log entry, but there isn't any traffic to the sinkhole IP. The action is sinkhole and reported as generic:malicious.domain1. I have confirmed that sinkhole does work for regular threat category dns and is reported as Suspicious DNS Query (generic:malicious.domain2).

mike406 by L2 Linker
  • 4996 Views
  • 1 replies
  • 0 Likes

Authorized file suddenly blocked as threat

We came into the office this morning to receive reports from users that they weren't able to access their core application which runs on apache web server. When they login, the internet explorer URL directs the users to www[whatever-url]com/login.jsp . Our clients download the file login.jsp when they access the login portal for the webpage. ...

Resolved! URL wildcard use

We have insufficent-content category blocked. And when trying to allow a specific url using wildcard i am having issues. when *.figuringoutmelody.com is used it is allowed on port 80 only while ssl gets blocked. website seems to redirect form www.figuringoutmelody.com to https://figuringoutmelody.comand when i used figuringoutmelody.com just as ...

image.png
image.png
raji_toor by L4 Transporter
  • 14260 Views
  • 2 replies
  • 0 Likes

MINEMELD CSV OUTPUT to ArcSight Logger SIEM

Hi, I've MineMeld running on Ubunto 14.04 TLS and everythings Ok.Cunfigured CEF output e now I'm looking for a CSV output, that is for inputing on ArcSight Logger in order to use this csv in Lookups to match events. Has anyone found/created any node output like this?Serached on github and here but withou success. Thanks

Fumaca14 by L0 Member
  • 3610 Views
  • 0 replies
  • 0 Likes

C&C Traffic Direction re China Chopper

Hi, sorry if this is a stupid question, maybe we need a Reddit-style "ELI5" forum ;o) I have been turning a blind eye to a background hum of China Chopper alerts for some time, so I thought I would try to understand what is going on. The thing is the threat reports are showing Inbound China Chopper C&C traffic to some of our servers. It's...

djr by L4 Transporter
  • 6576 Views
  • 2 replies
  • 0 Likes
  • 548 Posts
  • 80 Subscriptions