- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-05-2016 08:37 AM
Hi all,
We have seen in Wildfire Submissions that all files identified as Malicious and Grayware the action is Alert. The Wildfire Profile is configures to forward to public cloud and Antivirus profile has reset-both in Wilfdire Action tab.
Is this a normal work?
This is the Wildfire Submission
Thanks a lot,
Jordi
10-06-2016 04:06 AM
Hi Jordi
the test PE file will only allow you to verify if uploading and cloud analysis works for your deployment, it is not blocked as we don't generate signatures for the test file
also, in the wildfire submission log, action will always be alert (as it simply logs the upload), traffic and more specifically threat log will give you the action that was taken on the session itself (block)
10-06-2016 12:10 AM
Hi Jordi
This is possible if the file has not been seen by wildfire before: if a file is known to be malware, the antivirus profile action will be applied, so if you configured the profile to block, it will block the file. this will be logged in the threat log.
if the file is not known yet, it will need to be sent to wildfire for analysis first. because the file transfer needs to complete for the entire file to be uploaded to the cloud, the session will not get blocked. once the upload is completed, a log is created to indicate the file was uploaded. since the log is to indicate an upload to the cloud, the action in the wildfire submission logs will always be alert
10-06-2016 03:03 AM
Hi,
Thanks for your answer.
I think that our wildfire is not working correctly or is bad configured. Is rare that all actions are alert, there are no one block.
I have do wildfire test with http://wildfire.paloaltonetworks.com/publicapi/test/pe.
With the first download Paloalto identify the file as malware and action is block
After 30 minutes and new wildfire updates I put the same file to ftp and the result continues malware and action alert
Wildfire profile is configured as forward to public-cloud and Antivirus profile is configured as block.
Thanks,
Jordi
10-06-2016 04:06 AM
Hi Jordi
the test PE file will only allow you to verify if uploading and cloud analysis works for your deployment, it is not blocked as we don't generate signatures for the test file
also, in the wildfire submission log, action will always be alert (as it simply logs the upload), traffic and more specifically threat log will give you the action that was taken on the session itself (block)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!