Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
About Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.

Discussions

Welcome to the Threat & Vulnerability Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4392 Views
  • 0 replies
  • 0 Likes

Help with Microsoft DCE RPC Big Endian Evasion Vulnerability 33510

I have Googled this and read up on numerous links, but I cannot find anything of value on this threatID. I have 30-40 events a day from various IP addresses on my network, usually 1 event per IP, sometimes 2 events. I have scanned several of the PC's with 3 different popular scanners, nothing found. I have monitored the traffic from the PCs an...

smc007 by L1 Bithead
  • 7647 Views
  • 1 replies
  • 0 Likes

Blocked URL's are not getting blocked anymore

I configured a URL filering profile that doesnt filter any topic & just blocks 2 URL's as a test. This was working a few days ago but stopped. There have been no new changes commited since & the security policy is still in the same order. Even looking at the policy it makes no sense why this is not working. I have a security profile ...

Capture.PNG
Capture.PNG

Threat blocked by Palo Alto: Is there anything else to do?

Hi, When the Palo Alto blocks a communication that is flags as a threat (ie: SQL Injection, XSS, etc.), should we investigate the target IP to make sure that the threat was blocked? The reason I'm asking is that whenever the Palo Alto blocks an attack from an IP address (Session End Reason is "threat"), if we go in the "Traffic" view, we can see...

yschinck by L1 Bithead
  • 4932 Views
  • 2 replies
  • 0 Likes

Dynamic IP lists and FQDN?

The only type of external dynamic list i appear to be able to specify in my firewall policy is a dynamic IP list (not a dynamic domain list). And the formatting of such lists appears to be purely for IP addresses. So my question is, how can i specify fully qualified domain names in a dynamic list usable in a firewall policy?

Resolved! Query -> Data Center Best Practice Antivirus Profile

Hi Community. The below article states that "The Antivirus profile has decoders that detect and prevent viruses and malware from being transferred over six protocols: HTTP, SMTP, IMAP, POP3, FTP, and SMB": https://www.paloaltonetworks.com/documentation/81/best-practices/best-practices-data-center/data-center-best-practice-security-policy/how-to-...

ash83 by L2 Linker
  • 10778 Views
  • 7 replies
  • 0 Likes

URL Filtering Team creating MORE of a risk

Hi all, Does anyone know how to directly interact with the URL filtering team besides urlfiltering.paloaltonetworks.com? I would especially like to reach a manager. I am having huge problems with them. I keep submitting sites on which scanners have found malware (usually after one of my users visits them) and they keep refusing to recategoriz...

SSL DERYPTION : How to automate URL/domaine decryption Exclusion properly?

Use case : Ours users go through Palo alto for internet access. Decryption feaures has been enabled.When users try to access to internet may failed because the decryption-error.We need a solution to automate URL SSL decryption exclusion and log urls excluded for review. Perfectly in a dynamics external list or in a custom url category. Theses dy...

ingdrame by L0 Member
  • 6270 Views
  • 2 replies
  • 1 Likes

How Palo Alto Networks Identifies GnuTLS Server Hello Session ID Heap Buffer Over Without Decryption

HI All, We detected Vulnerability: 36926 ID- GnuTLS Server Hello Session ID Heap Buffer Overflow in Palo Alto firewall. In our cutomers Firewall enviroment we not enable the SSL Descryption Feature. Customers Queries us.. How and Why Palo Alto able detect the Vulnerability threat without the SSL? Can Any one assist us on this?

Nono by L1 Bithead
  • 5662 Views
  • 1 replies
  • 0 Likes

PAN-DB Connectivity

Hi, We are faced with the connectivity issue when we tried to download the URL filtering DB from PAN-DB. As the firewall has an external interface to the internet, we have changed the service route for “Palo Alto Networks Services” to the external interface. However, we are not able to get connected to the PAN-DB. We are able to ping to the PAN-...

  • 548 Posts
  • 80 Subscriptions