Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.
About Advanced Threat Prevention Discussions
Welcome to the Advanced Threat Prevention discussion area. Here, we explore Precision AI-powered protection that stops zero-day malware, exploits, and command-and-control attacks in real time—ensuring proactive defense and resilience against today’s most sophisticated threats.

Discussions

Welcome to the Threat & Vulnerability Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4385 Views
  • 0 replies
  • 0 Likes

Wrong behavior of Advanced URL filter

Dear experts, Here is my question: Our customer has registered new URL domains and configured the firewall to block all newly registered domains via the URL filtering configuration. They noticed that the new domain is NOT blocked right away but about 15 minutes after the first time it becomes reachable. Is this behavior expected? The customer ...

Resolved! Cannot update Adobe Creative Cloud

We cannot update Adobe Creative cloud when on our network or Global protect. What I'm seeing is in the Threat logs for adobe-creative-cloud-base threat ID 678983911, content version Antivirus-4995-5513, ccmdls.adobe.com/AdobeProducts/KCCC/1/win64/packages/ACCC_6_4_0_ADS_361/ADS.zip Name: Virus/Win32.WGeneric.ekybxu Unique Threat ID: 67898391...

ksauer507 by L3 Networker
  • 7779 Views
  • 2 replies
  • 0 Likes

Open port 9339 - CVE-2016-2183

Hi, After the update PA to version 11.1.0 (currently we are using version 11.1.1 but the problem still exists), Nessus discovered open TCP port 9339 and alerted about vulnerability SWEET32 (screen attached below). It is weird, because port 9339 is up despite of the fact that LLDP is disabled in our configuration (screen attached below):

image.png
image.png
PatrykChodurski_1-1704963348299.png

Resolved! Geolocation Address Groups

Does anyone know if you can create Geo-location address groups? I want to create a group for all the bad Countries instead of having to add all the Countries to every Geo-location rule. Example: Add Russia, Crimea, North Korea, Iran, etc.. into a "Bad Countries" group then apply that group into my inbound / outbound Geo-fencing rules.As of now ...

JeffNeff by L0 Member
  • 6428 Views
  • 2 replies
  • 1 Likes

Azure Microsoft Defender Security Warnings

Recently Microsoft Defender for Cloud has started reporting various files in our palo alto as malware. The most recent one today is hdd/mfa1z5om.aa2/tmp and hdd/mfa1z5om.aa2/usr/sbin as Trojan:Linux/Casdet!rfn. There have been daily alerts with various types of malware over the last week, is this an actual infection or is it just detecting the v...

VA issue

Is there anyway to solve those VA issue? 1) 90317 - SSH Weak Algorithms Supported2) 42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)3) 70658 - SSH Server CBC Mode Ciphers Enabled4) 71049 - SSH Weak MAC Algorithms Enabled Kindly help please..Thank you

Vector by L0 Member
  • 5835 Views
  • 2 replies
  • 0 Likes

Can you setup a failure grace period for CI image scans based on first found date

I'm looking for a way to set a failure grace period for CI image scans based on the first found date. I see in the rulesets you can set a failure grace period based on the first fix date. For example, if we were to set an expectation that any high finding needs fixed within 30 days of being detected (from the initial scan date), and we don't ...

Threat Prevention Rules, Exceptions, Default Actions Precedence

I want to confirm the order of precedence for security profile rules, default actions, and exceptions. For example, the default action for the SSH User Authentication Brute Force Attempt threat is alert. However, the threat profile rule associated (simple-server-high) has an action of reset-both. I think the rule action will override the defa...

  • 548 Posts
  • 80 Subscriptions
Top Liked Authors