WildFire API Malware Hashes

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

WildFire API Malware Hashes

L2 Linker

I'm trying to get the file hash values for all submissions WildFire deems as malware.  Is this possible?  From what I've read you have to specify the hash value in the API call but I'd just like a list of all values.

1 accepted solution

Accepted Solutions

As @pulukas said, you can't do this with the WildFire API, but there are a couple other solutions:

 

1. The sha256 hashes are available on the Firewalls/Panorama.  They can output via syslog or webhook as they happen, or you can query them via the PAN-OS API.

https://www.paloaltonetworks.com/documentation/81/pan-os/xml-api/pan-os-xml-api-request-types/retrie...

 

2. AutoFocus subscribers can get a list of hashes via the AutoFocus API.  Here's an example request for hashes of all 'private' malware samples, which means all samples submitted by your organization to WildFire:

https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-s...

 

And an example result showing the sha256, md5, and sha1 hashes of one of the samples returned:

https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-s...

View solution in original post

3 REPLIES 3

L7 Applicator

I don't think you can.  The idea of the API is to query for an Ad Hoc verdict not to pull the data for a separate or offline solution.

 

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

As @pulukas said, you can't do this with the WildFire API, but there are a couple other solutions:

 

1. The sha256 hashes are available on the Firewalls/Panorama.  They can output via syslog or webhook as they happen, or you can query them via the PAN-OS API.

https://www.paloaltonetworks.com/documentation/81/pan-os/xml-api/pan-os-xml-api-request-types/retrie...

 

2. AutoFocus subscribers can get a list of hashes via the AutoFocus API.  Here's an example request for hashes of all 'private' malware samples, which means all samples submitted by your organization to WildFire:

https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-s...

 

And an example result showing the sha256, md5, and sha1 hashes of one of the samples returned:

https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-s...

L2 Linker

Thanks for the options.  I forgot about API and will go that route as we're still on 7.1 and not yet an AutoFocus subscriber.

  • 1 accepted solution
  • 3881 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!