- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-13-2024 03:06 AM
Hi team
We are detecting some files with Verdict "malicious" and action "allow"
Can anybody help us for change the action or other solution?
Regards
05-13-2024 05:51 AM
WildFire log?
If you click on the magnifying glass, WildFire Analysis Report tab then what does "First Seen Timestamp" show?
WildFire will pass through the malicious file on first instance it sees the file and when verdict comes back from the sandbox it will show if verdict was benign or not. So in those cases you need to analyze workstation to check if it got infected.
Starting from 11.0.2 there is new feature "Hold Mode for WildFire Real-Time Signature Lookup"
05-13-2024 05:51 AM
WildFire log?
If you click on the magnifying glass, WildFire Analysis Report tab then what does "First Seen Timestamp" show?
WildFire will pass through the malicious file on first instance it sees the file and when verdict comes back from the sandbox it will show if verdict was benign or not. So in those cases you need to analyze workstation to check if it got infected.
Starting from 11.0.2 there is new feature "Hold Mode for WildFire Real-Time Signature Lookup"
05-21-2024 12:41 AM
We have wildfire real-time configured and the action is reset-both but we are seeing that the first time the veredict is benign, one the signature is created the veredict changes to malicious but the result keeps being "allow", Is that correct? Is there any way to block this malicious files?
05-21-2024 04:27 AM
Hi @JuanMAbellan ,
This is expected. Please check into the feature Hold Mode for WildFire Real-Time Signature Lookup as mentioned by @Raido_Rattameister .
With this feature you can prevent the initial transfer of known malware.
Kind regards,
-Kim.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!