Cloud Delivered Security Services
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Palo Alto Networks’ Cloud Delivered Security Services.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Cloud Delivered Security Services
Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Palo Alto Networks’ Cloud Delivered Security Services.

Browse the Community

Threat & Vulnerability

This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.

538 Posts

Endpoint (Traps) Discussions

Traps Advanced Endpoint Protection prevents cyber breaches by protecting and enabling users to conduct their daily activities, and automating prevention by autonomously reprogramming itself using threat intelligence gained from WildFire.

22 Posts

Enterprise Data Loss Prevention Discussions

A forum to ask or share about Data Loss Prevention (DLP) strategy. DLP ensures sensitive or confidential information doesn't leak outside of the corporate network. Let's rethink DPL together.

15 Posts

Next-Generation CASB Discussions

This forum is to discuss Palo Alto Networks' Next-Generation CASB, an integrated, multi-faceted CASB solution that helps security teams meet the security challenges of today.

15 Posts

IoT Security Discussions

Discussions about IoT Security — aka the Internet of Things — a cybersecurity strategy that safeguards against the possibility of cyberattacks which specifically target physical IoT devices that are connected to the network.

29 Posts

AI Access Security Discussions

Welcome to the AI Access Security discussion area! Here, we focus on how AI Access Security facilitates safe Generative AI adoption by providing real-time visibility, streamlined access control, and robust data protection. Join us to share insights and discuss strategies for keeping sensitive information secure in AI applications.

3 Posts

Advanced DNS Security Discussions

Welcome to the Advanced DNS Security discussion area. Here, we focus on delivering real-time, AI-powered protection against DNS-layer threats—ensuring visibility, control, and prevention across all network environments.

1 Posts

Activity in Cloud Delivered Security Services

Threat ID 31671 - SCADA ICCP Unauthorized COTP Connection Established

I think the description of "Threat ID: 31671 - SCADA ICCP Unauthorized COTP Connection Established" is incorrect. Below is the description of the Threat, but it describes a successful connection there doesn't seem to be anything malicious to it. I'm thinking more should have been added to the description to describe why the threat is malicious. ...

K.Nand by L0 Member
  • 2713 Views
  • 1 replies
  • 0 Likes

SNMP not polling PA-VM

Configured device for SNMP polling. Checked devices in path to ensure they weren't blocking traffic. I can ping the device just fine. However, I am unable to complete discovery and I see no traffic in the traffic logs for port 161/162.

Kmshae by L0 Member
  • 184 Views
  • 1 replies
  • 0 Likes

DNS Traffic slow/time out after applying Anti Spyware

Hi everyone,We are using PAN OS 9.1.5.Our internal hosts and DNS server are in different PA Zones.We have a policy to allow all hosts to access DNS servers with application "dns".We used strict anti spyware profile on the above mentioned security policy.After applying anti-spyware profile, we see that the DNS queries timeout most of the times an...

High alert with signature

Hello, I'm sending out a message in a bottle — I'm noticing a very high number of false positives on signatures with a high severity level, whether they are Anti-Spyware or Vulnerability Protection signatures. The issue is that the solution doesn't implement a scoring system to determine the relevance of its alerts. I'm wondering if anyone has...

Inquiry About Building and Publishing a Cortex XDR Integration

Hi Team,We have a customer interested in developing a data connector for Cortex XDR, with the intention of making it publicly available via the Cortex XDR Marketplace. Our team will take full ownership of the development process, and we’d appreciate your guidance on best practices, platform limitations, and the overall integration and publishing...

Palo Alto EDLP Nested Data Profile Incident shows incorrect count of occurances

why the Nested Profile Incident in Palo Alto EDLP doesn't show the correct keyword count, while the Nested Data Profile test does.1. I created Nested profile. Test for Nested Data Profile shows correct count of occurances.however when pushed through Panorama, Incident Got generated, but count of occurances of keywords is not accurate.2. And not ...

Threat ID: 31671 - SCADA ICCP Unauthorized COTP Connection Established

SCADA, or Supervisory Control and Data Acquisition, systems are critical industrial control systems that monitor and manage sensitive processes. This alert, "Threat ID: 31671 - SCADA ICCP Unauthorized COTP Connection Established," signifies that an unauthorized ICCP (Inter-Control Center Communications Protocol) client has successfully establish...

Palo IOT - Get the Device Inventory API Endpoint

Hello, interested in exporting device list from iot platform. I see a API endpoint for this but it doesn't have examples or document how to do filtering or page next since the it is capped to 1000 devices per request. please advise. https://pan.dev/iot/api/device-inventory/ > https://api.strata.paloaltonetworks.com/pub/v1/device/list ...

Palo Alto OT security limitation for mobile devices

Hello Everyone, What does Discover Mobile Device Attributes the limitation mean? ========== IoT Security can learn mobile (cellular) device attributes, add the devices to its inventory, and track them by the IMEI numbers. You can then see various mobile device attributes for them on the AssetsDevices and Device Details pages. You can also ...

Register or Sign-in