- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-03-2014 06:50 AM
If we are given a document which shows specific files used by bad actors in our sector, is it possible to have the PAN alert/block on these files? I have the SHA256 and MD5 hashes.
09-03-2014 08:31 AM
Hello mackwage,
You may also create a custom vulnerability signatures to prevent the downloading of specific file names. Such as Bad-Filename.zip or xyz.exe.
Please follow this document:Creating Custom Threat Signatures
Hope this helps.
Thanks
09-03-2014 08:20 AM
Hi Mackwage,
AFAK, there is no way to do it, not even through custom signature. Because there is no option to specify file Hash.
Why do you want to block a good file.
Regards,
Hardik Shah
09-03-2014 08:20 AM
Hello Macwage,
I don't think it is possible to block or alert file based on the hash value. You may post a query to DevCenter for the same.
Thanks
09-03-2014 08:23 AM
Thanks! Is Data Filtering the best way to attempt to block by filename?
09-03-2014 08:28 AM
A similar discussion for your reference: Re: Anyone Blocked a specific file from being downloaded?
Thanks
09-03-2014 08:31 AM
Hello mackwage,
You may also create a custom vulnerability signatures to prevent the downloading of specific file names. Such as Bad-Filename.zip or xyz.exe.
Please follow this document:Creating Custom Threat Signatures
Hope this helps.
Thanks
09-03-2014 08:31 AM
Hi Mackwage,
For any special configuration, always try custom signature. Unfortunately you dont have option to block any file based on special Hash.
You can follow bellow information for custom signature.
Regards,
Hardik Shah
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!