Scanning network flow using file name

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Scanning network flow using file name

L3 Networker

Hello,

Any know an opportunity to scan network flow with PaloAlto to find files by file name? Eg.: i entered "angry tiger" and i find all files (including all file types) with that name sent over the network.

1 accepted solution

Accepted Solutions

I found one solution: i must log all file types using File Blocking profile (File Type -> any, Action -> alert) and then in a Data Filtering log i can find file using file name. Not ideal, but works Smiley Happy

View solution in original post

7 REPLIES 7

L4 Transporter

Hello,

We see that you are looking for certain text and you are receiving all files with all file types. If there is a filter to be made for certain file types we will have to use the file blocking profile as explained below.

https://live.paloaltonetworks.com/docs/DOC-3094

You can also create custom vulnerability by creating custom signature for matching a certain pattern of text in files so that the PAN can search for these texts and when matches logs with the custom vulnerability on the device.

Thanks

Thanks for answers. So as i understand, no way to find file using file name. Or anyone has other ideas?

Let me explain more what i want: If someone sent a file: angry_tiger.doc or angry_tiger.mp3, or angry_tiger.avi, or angry_tiger.*(any file type). Can i some how find that file using file name "angry_tiger"?

Please follow below mentioned discussion for more info:

https://live.paloaltonetworks.com/message/3553#3553


Hope it helps.

Thanks

Hi,

If you want to search file name, you ave to go through data filtering profile.

The easiest way to do it is to use regex? With this method you can search all what you want.

Eg: https://live.paloaltonetworks.com/docs/DOC-4860.

Just keep in mind that you can't search string with size  under 7.

Hope help.

V.

I found one solution: i must log all file types using File Blocking profile (File Type -> any, Action -> alert) and then in a Data Filtering log i can find file using file name. Not ideal, but works Smiley Happy

Hi,

yes you can do that, very usefull for auditing 🙂

Maybe upload logs to syslog server and make a script for sending an alert

V.

  • 1 accepted solution
  • 4326 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!