- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-13-2026 12:32 AM
Hi @hitachisas
The default action for each Threat ID is determined by the Palo Alto Networks Threat Research team based on their internal evaluation criteria and several metrics. These criteria include the type of vulnerability, its impact, and its severity.
In some cases, you may see Threat IDs with High or Critical severity set to “Alert” as the default action. This is common for newly released threats, such as new CVEs or signatures. They are initially set to “Alert” for monitoring and observation. In later updates, the default action may be changed to “Reset” or "BLOCK" action if needed.
You can review Threat ID details, including severity and default actions, directly on the firewall (ensure the latest Threat content update is installed) or on ThreatVault
If required, you can manually override the default action and set a specific Threat ID to “Block” or “Reset.” This reference article will help you on it.
Hope it helps!