Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
cancel
Showing results for 
Search instead for 
Did you mean: 
Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
About Threat & Vulnerability Discussions

Welcome to the Threat and Vulnerability discussion forum. This forum exists as a resource for security professionals to discuss and share information pertaining to the topics of threats and vulnerabilities.
Not a LIVEcommunity member? Simply click here and register!

Discussions

Understanding Security Profiles

 

PA newbie here!  I am digging in to the PA traffic processing algorithm & on the 4th leg of the process I see that the traffic is allowed at this point but gets scanned against the configured security profile.  This sounds like where IPS comes into

...

PA-v.PNG

add new Certificate for web APP

Good day!

  I tried to follow the steps to create SSL Inbound Inspection but after I added the certificate for the first application (EPOS it’s name) , it’s not showing inside decryption policy role, please check the below pictures to make the image c

...

1.png
2.png
o.othman by L0 Member
  • 1827 Views
  • 0 replies
  • 0 Likes

Blocking SMB Traffic

I was doing a review of some firewall policies and noticed the company I am consulting for is allowing all applications risk 1 through 3 from their trust to untrust zones.  Not sure why it's setup that way yet, but in doing so, SMB traffic is alllowe

...

ce1028 by L4 Transporter
  • 11299 Views
  • 8 replies
  • 0 Likes

Resolved! False Positive AV block

Hi,
Not sure if this is under the correct category but here we go.
I have a false positive in my FWs, I have a file called Pv7_00_169SetupFull.exe which the FWs are detecting as Virus/Win32.WGeneric.qxdip

If I upload and scan the file with VirusTotal it

...

GOTRIDA by L0 Member
  • 3433 Views
  • 1 replies
  • 0 Likes

Resolved! Thread-Log: Virus found

Hello,
under our Threat-Log I found some Virus entries. The Attacker is an own PC from another vlan. We want to install windows updates over Ivanti-Patchmanagement with the original windows update service. And now the maschine, which we will patch, wi

...

Resolved! Palo Alto Negate Object Meaning

Hi,

 

I have a question on Palo Alto negate object. If I have a allow rule that allow src zone A, src IP of 10.10.10.0/24 (Negate) to dst zone B, dest IP of ANY.

 

Does it mean that the rule is allowing other src IP (not including 10.10.10.0/24) from src

...

Risk 0 for workday and service now.

Hi, 

I noticed in our ACC dashborad that the applicaitons in use such as workday and servicenow were assigned a risk of 0.  Is that becuase they have not been identified as risky apps or thats the lowest risk level which means no threat app.  

 

Thank y

...

TCP SYN with data Threat logs

Hi Guys,

 

I receive hundreds of TCP SYN with data Threat Alerts from my BYOD zone every day. I was learning more about it and I understood that it is a TCP syn packet with data in its payload. However, as almost all of them seems to come from non-mali

...

Resolved! Dynamic IP List import now failed

I just have the two default PA dynamic IP lists, but they each only have roughly 100 IPs.  I would think there would be more than that but when I try to hit 'import now' it just fails.  Anyone shed some light on how these two lists work and how often

...

drewdown by L4 Transporter
  • 16561 Views
  • 15 replies
  • 0 Likes