block http download based on the download file hash value

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

block http download based on the download file hash value

L4 Transporter

Dear all,

 

I have asked to look for a solution,  we want to receive alert based on specific file download via http, we have the file MD5 or SHA1 hash value.   Can I do this with a PAN?  The filename could change,  I don't know the file size but I have the file hash value..

 

Thanks for your helps in advanced,

 

3 REPLIES 3

L5 Sessionator

If you want to block/alert a file with hash value it is not possible.

Cyber Elite
Cyber Elite

Hi E

 

The Palo Alto Networks firewall performs stream-based inspection of file transfers, so no proxy functionality is applied, hence no sha or md hash is collected. We can, however, identify files by all kinds of other means. Could there perhaps be any other identifiable markers, watermarks, headers, propietary strings of data in the file? these could be easily added to a custom app or threat profile, or as a data filtering profile.

 

regards

Tom

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L6 Presenter

Hi...One option is to use WildFire subscription to upload all interesting file to our WildFire cloud for analysis.  From its portal you can see all the files and find the file to match your MD5 hash.

  • 2149 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!