Submit a New Threat

Reply
Highlighted
L0 Member

Submit a New Threat

Hello,

 

My IDS has detected a new Angler signature on my network and it was allowed by my PA firewall. The traffic was allowed being the IDS is not inline. How do I submit packets for a threat update/addition?

Highlighted
L4 Transporter

Bkluth:

 

This forum is for custom signature creation; for official content requests for PAN supported content coverage, please open a support case through the traditional process and provide all data gathered.

 

If you're interested in a custom signature creation for this type of traffic, you can provide it here.

Highlighted
L0 Member

Ok. Thank you for the clarification, although I cannot select a device to receive support for after selecting, "new case." There isn't a streamlined way to submit new threats? That's odd.

Highlighted
L4 Transporter

Bkluth:

 

The current method for reporting new threats and missed detection is to have a support case opened and ask to work with a threat specialist, where we will triage the issue and work with our research and development team to assist you in every way possible to close any gaps in coverage, provided that actionable data is available.

 

There are automated methods for submitting URL recategorization for malware sites, but currently working with the threat speciailist division of the support team designed to assist you is the most effective avenue.

 

If you are having trouble creating a case, Support <Support@paloaltonetworks.com> can assist you with this process, as our CSR folks are very experienced at addressing support accessibility issues.

Highlighted
L4 Transporter

bkluth,

 

As a best practice we put all IP addresses hosting an exploit kit (Angler, Rig or Nuclear)  on a dynamic blocklist we do this upon notification of the IPS log event.  Looking at all traffic going to the site that is hosting the exploit kit sometimes shows other users going there.  The Impact to them is not known as there is sometimes no IPS event, no files coming down and sometimes no other network behaviors.  Our rationale is that there is nothing good at that IP address.

 

Phil

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!