Wildfire verdict malicious and action alert

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Wildfire verdict malicious and action alert

L2 Linker

Hi all,

 

We have seen in Wildfire Submissions that all files identified as Malicious and Grayware the action is Alert. The Wildfire Profile is configures to forward to public cloud and Antivirus profile has reset-both in Wilfdire Action tab.

 

Is this a normal work?

 

This is the Wildfire Submission

 

image.png

Thanks a lot,

Jordi

 

1 accepted solution

Accepted Solutions

Hi Jordi

 

the test PE file will only allow you to verify if uploading and cloud analysis works for your deployment, it is not blocked as we don't generate signatures for the test file

 

also, in the wildfire submission log, action will always be alert (as it simply logs the upload), traffic and more specifically threat log will give you the action that was taken on the session itself (block)

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Hi Jordi

 

This is possible if the file has not been seen by wildfire before: if a file is known to be malware, the antivirus profile action will be applied, so if you configured the profile to block, it will block the file. this will be logged in the threat log.

 

if the file is not known yet, it will need to be sent to wildfire for analysis first. because the file transfer needs to complete for the entire file to be uploaded to the cloud, the session will not get blocked. once the upload is completed, a log is created to indicate the file was uploaded. since the log is to indicate an upload to the cloud, the action in the wildfire submission logs will always be alert

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi,

 

Thanks for your answer.

 

I think that our wildfire is not working correctly or is bad configured. Is rare that all actions are alert, there are no one block.

 

I have do wildfire test with http://wildfire.paloaltonetworks.com/publicapi/test/pe.

With the first download Paloalto identify the file as malware and action is block

 

WF first download.png

 

After 30 minutes and new wildfire updates I put the same file to ftp and the result continues malware and action alert

 

WF to ftp.png

 

Wildfire profile is configured as forward to public-cloud and Antivirus profile is configured as block.

 

 

 

Thanks,

Jordi

 

 

Hi Jordi

 

the test PE file will only allow you to verify if uploading and cloud analysis works for your deployment, it is not blocked as we don't generate signatures for the test file

 

also, in the wildfire submission log, action will always be alert (as it simply logs the upload), traffic and more specifically threat log will give you the action that was taken on the session itself (block)

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 3854 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!