False Positive Virus PDF

cancel
Showing results for 
Search instead for 
Did you mean: 

False Positive Virus PDF

L3 Networker

Hello,
We are detecting that several PDFs that we share on our internal network are being detected as VIRUS.

As we have the antivirus profile enabled in a security rule the session is reset .

Does anyone know how I can avoid this?

Regards

2 REPLIES 2

Community Team Member

Hi @Alpalo ,

 

If this is a false positive you should gather the PCAP from the threat log and send it to support for analysis so they can get the signature fixed.  If packet capture isn't enabled then you can enable it in the security profile.

 

As a workaround you can create an exception until the false positive is fixed:

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/threat-prevention/create-threat-exception...

 

Hope it helps,

-Kiwi.

 

 

Cyber Elite
Cyber Elite

Hello,

Also if its being detected as one of the 'generic' definitions, then most likely its a false positive. Happens from time to time as the generic definitions are quit broad.

Regards,

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!