- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-07-2020 02:42 PM
Hello,
Writing custom signatures is something I always leave to the vendors, its their job :). If you setup your PAN with the everything turned on, anti-virus, spyware, url filtering, dns sinkhole, using secure dns (even if it snot PAN's), SSL Decrypt, wildfire, tight policies, I think you will find not much if anything can get through. Also enable the telemetry to be sent to PAN, it helps hem write signatures for everyone :), a small way to give back.
Also use best practices on the rest of the network as well as endpoints (AV etc).
You can always use their threat db to search and see if they already have something. If they dont put in a TAC request and they'll work on one.
https://threatvault.paloaltonetworks.com/
Regards,