cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

L3 Networker

Hi @jesusyas,

 

To further assess if the verdict reported is a false positive, details of the WildFire analysis can be reviewed. To open the WildFire Analysis Report:

 

  1. Navigate to the relevant incident. Right-click the Incident and select “View Incident”
  2. From the “Key Artifacts” list incorporated with the Incident, select the report icon as demonstrated. This will take you to the WildFire Analysis Report.

mfakhouri_1-1664820602324.png

 

This report will contain detailed sample information leading up to the case of the WildFire verdict. 

 

If the verdict is determined to be a false positive, a report can be made at the top right of the WildFire Analysis Report menu. This will report the error to our threat team.

 

 

mfakhouri_3-1664820602337.png

 

If you are still unable to confirm the validity of the detected file, we highly recommend submitting a support ticket to identify and remediate the issue at support.paloaltonetworks.com. This will ensure that the issue is documented and a fix is implemented if there is a false positive.

 

Reference:

https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-respo...

View solution in original post

Who rated this post