cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

Who Me Too'd this topic

Spyware Detections

L1 Bithead

Hi Community,

 

Lately we are noticing on one of our clients environment where PA is flagging traffic to "mail.google.com" as Spyware. The captured signature is "sliver framework command and control traffic detection".

 

I did run the captured URL "mail.google.com/sync/u/0/i/bv?hl=en&c=31&rt=r&pt=ji" on both, Virustotal and Palo Alto's AutoFocus. Both resulted in benign. However, we have received more then 100 alerts in last 24 hours for same signature and similar URL on our SIEM.

 

I wanted to know if this  is a FP detection and signature has to be requested for re-classification. Anyone else experiencing similar issue?

 

Thanks

Who Me Too'd this topic