Wildfire Verdict benign / Action block

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Wildfire Verdict benign / Action block

L1 Bithead

I'd like to understand how Wildfire works. I have this example where Verdict is benign and action is block. Why?

 

PA1.png

 

PA2.png

1 accepted solution

Accepted Solutions

@Keny_Schmeling,

What likely happended was the firewall identified the traffic via a signature or local analysis and determined that it was malicious; when it was sent to the wildfire cloud and actually ran in the sandbox environment it was discovered to be benign. Therefore the verdict would report benign, because it is, but the firewall would have blocked the traffic before the file was sent off to be analyzed. 

Now if the hash of the file is seen by your firewall again, it will allow the file as the hash is known to be benign. Likewise, if I attempted to download the same file on my firewall it would also be allowed, because you've already analyzed the file and the hash is known to be benign. 

View solution in original post

2 REPLIES 2

L1 Bithead

Filtering by Session ID I have this logs:

 

PA3.png

@Keny_Schmeling,

What likely happended was the firewall identified the traffic via a signature or local analysis and determined that it was malicious; when it was sent to the wildfire cloud and actually ran in the sandbox environment it was discovered to be benign. Therefore the verdict would report benign, because it is, but the firewall would have blocked the traffic before the file was sent off to be analyzed. 

Now if the hash of the file is seen by your firewall again, it will allow the file as the hash is known to be benign. Likewise, if I attempted to download the same file on my firewall it would also be allowed, because you've already analyzed the file and the hash is known to be benign. 

  • 1 accepted solution
  • 5876 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!