Wildfire Signature creation

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Wildfire Signature creation

L4 Transporter

Can someone share some facts about the process of the WF signature creation. It was promised by PAN to have a signature ready after 15Mins. a sample has been identified as malicious (Verdict Malware). My observation is that it usually takes much longer than that. We do have a WF subscription.

Example in the screenshot below.

Capture.JPG

9 REPLIES 9

L5 Sessionator

Hi @gafrol,

Sometimes when you see file marked as malicious in wildfire and even after 15-30 minutes if you are able to download the file, one of the reason it might be due to signature generated off the file in question. This might be deemed false positive and would not be added to distributed signature list. Where as wildifire still categorized as malicious. You can dispute the verdict via wildfire or open a support case for further analysis. Hope this helps. Thank you.

The above sample was neither a false positive nor an incorrect verdict. It is clearly malicious and as such identified by Wildfire. It took more than 24 hours to have a WF signature ready for deployment. This is not an exception, I observe many of these "delayed" WF signatures, which is a rather strong deviation from what is promised by Marketing.

Hi @gafrol,

For such cases I would suggest opening support case, so we can look at individual instance to see why it took more time than usual for signature distribution. If there is an issue, it will help us to fix the issue in future as well. If it was expected, then we can inform you with the reason. Hope this helps. Thank you.

I already opened a case two days ago, no answer so far. Seems to be difficult to answer this one ....

BTW where are all the release notes for the WF signatures ? On the PAN FW's I only find the two most recent WF RN's....

Capture.JPG

This does not add any transparency for customers at all. Also what is the timezone given in the "Date Released" field ?

Capture.JPG

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!