Custom Signatures
The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Custom Signatures
The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.
About Custom Signatures

Welcome to the Custom Signatures discussion forum. This forum exists as a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance. Please feel free to engage with other community members and Palo Alto Networks staff. Ideas, questions, research, and observations regarding the process of custom signature creation are all actively encouraged.

For an introduction to the forum, please see the sticky!

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to custom signatures. Please use the information from this forum at your own risk and make sure to test and verify any signature and code presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Palo Alto Threat Vault AntiVirus Signatures

Hi Community!

 

I wanted to better understand how Palo Alto ties it's detections with its Unique Threat ID to the Wildfire Virus Detections. 

 

For example, we have been receiving a steady amount of alerting for a Virus File and Palo Alto gives us th

...

Brute Force GlobalProtect Portal via GP app

I'm looking for a way to define a custom signature that can detect brute force attempts on the GlobalProtect portal that aren't based on the portal login page. I already have ID 40017 - VPN: Palo Alto Networks SSL VPN Authentication Brute Force Attem

...

alexg_8_3-1679925356788.png
alexg_8_2-1679925327162.png
alexg_8_4-1679925519836.png
alexg_8 by L1 Bithead
  • 3179 Views
  • 3 replies
  • 2 Likes

Palo Alto Reponse to CVE-2023-48795

Hi all! I am curious whether  anyone knows if Palo Alto has any made any response to CVE-2023-48795? This vulnerabilities has been out for awhile and other vendors have already provided some types of response however, I am not able to find one from P

...

We updated the dynamic antivirus database and threats, but it failed

I've been waiting for 3 days to get help !

 

 

 

My introduction is Mr. Dwi

From PT. Tabsolutions

Indonesia

This is my device

 

Device Name                      : PA-3020-PLN

Software Version              : 9.1.16

Globalprotect Agent        : 5.2.12

...

dwi by L0 Member
  • 684 Views
  • 2 replies
  • 0 Likes

creation of custom app id

Hello everybody, i need to create custom app id in firewall for only gives access to get method while api call, but when i wrote signature i can not define the contex of the method in http request.Any help?

Regarding for reason and detect contents.

What communications does this rule detect?

I want to confirm is correct an answer by user.

Answer by user: In order to split the CSV, I created and executed "extract.bat".

 

Detection Rule:

・Behavioral threat detected (rule: powershell_cradles.b)

 

s

...

Customizing Response pages

Need help in identifying a document with all the variables listed to customize response page. This customization is to inform users, the reason why the URL is blocked

Issues Creating Custom App

In order to allow Updates to OneDrive im trying to create a custom application. (since I'm blocking PE) as it is detected as web-browsing. It does not detect that ms one drive premade application. 

 

I created a custom signature with the Client hello

...

signature based http-req-message-body

HI all,

I'm trying to create a custom signature based on the POST payload the client is sending.

This is the POST collected from the server:

 

POST /pds HTTP/1.1 Accept: application/x-ms-application, image/jpeg, application/xaml+xml, image/gif, image...

body.png

Resolved! Custom Vulnerability to Block Old Browser Versions

Would anyone know how to properly identify and block old browser versions using custom vulnerability object? I need help with the proper "pattern" to use to be able to identify the version. I know that there is the following guide:

https://knowledgeba

...

RyanViq by L0 Member
  • 3805 Views
  • 3 replies
  • 0 Likes