10-26-2018 08:30 AM
As per Admin guide
The Palo Alto Networks WildFire system also provides signatures for persistent threats that are more evasive and have not yet been discovered by other antivirus solutions. As threats are discovered by WildFire, signatures are quickly created and then integrated into the standard Antivirus signatures that can be downloaded by Threat Prevention subscribers on a daily basis (sub-hourly for WildFire subscribers
Does it mean that WF if does not know any Antivirus signature it quickly creates it and when we have 5 mins update with
WF cloud that new signature comes and becomes part of antivirus profile only.
Need to know when new signature comes from WF it is only for the Antivirus profile?
10-26-2018 02:47 PM
In the wildfire log the action is only based on the fact if there is already a WF signature. So for every WF log entry with action block you also have a threat log entry either as virus or wildfire-virus. Thats also the reason why (also in your screenshot) you have malicious files with action allow. These with action allow are the ones where so far isn't a WF signature available.
Another reason why a signature is required is because paloalto firewalls are still stream based, they block the file already when the signature matches a part of the file, at that point the file doesn't have to be fully transfered.
01-10-2022 01:28 AM
Which functionality is available to firewall users with an active Threat Prevention subscription, but no
WildFire license? Access to the WildFire API or PE file upload to WildFire?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!