- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
10-02-2018 03:34 PM
I'd like to understand how Wildfire works. I have this example where Verdict is benign and action is block. Why?
10-03-2018 08:06 AM
What likely happended was the firewall identified the traffic via a signature or local analysis and determined that it was malicious; when it was sent to the wildfire cloud and actually ran in the sandbox environment it was discovered to be benign. Therefore the verdict would report benign, because it is, but the firewall would have blocked the traffic before the file was sent off to be analyzed.
Now if the hash of the file is seen by your firewall again, it will allow the file as the hash is known to be benign. Likewise, if I attempted to download the same file on my firewall it would also be allowed, because you've already analyzed the file and the hash is known to be benign.
10-02-2018 03:42 PM
Filtering by Session ID I have this logs:
10-03-2018 08:06 AM
What likely happended was the firewall identified the traffic via a signature or local analysis and determined that it was malicious; when it was sent to the wildfire cloud and actually ran in the sandbox environment it was discovered to be benign. Therefore the verdict would report benign, because it is, but the firewall would have blocked the traffic before the file was sent off to be analyzed.
Now if the hash of the file is seen by your firewall again, it will allow the file as the hash is known to be benign. Likewise, if I attempted to download the same file on my firewall it would also be allowed, because you've already analyzed the file and the hash is known to be benign.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!