Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
About Threat & Vulnerability Discussions

Welcome to the Threat and Vulnerability discussion forum. This forum exists as a resource for security professionals to discuss and share information pertaining to the topics of threats and vulnerabilities.
Not a LIVEcommunity member? Simply click here and register!

Discussions

Blocking SMB Traffic

I was doing a review of some firewall policies and noticed the company I am consulting for is allowing all applications risk 1 through 3 from their trust to untrust zones.  Not sure why it's setup that way yet, but in doing so, SMB traffic is alllowe

...

ce1028 by L4 Transporter
  • 16234 Views
  • 8 replies
  • 0 Likes

Resolved! False Positive AV block

Hi,
Not sure if this is under the correct category but here we go.
I have a false positive in my FWs, I have a file called Pv7_00_169SetupFull.exe which the FWs are detecting as Virus/Win32.WGeneric.qxdip

If I upload and scan the file with VirusTotal it

...

GOTRIDA by L0 Member
  • 4555 Views
  • 1 replies
  • 0 Likes

Resolved! Thread-Log: Virus found

Hello,
under our Threat-Log I found some Virus entries. The Attacker is an own PC from another vlan. We want to install windows updates over Ivanti-Patchmanagement with the original windows update service. And now the maschine, which we will patch, wi

...

Resolved! Palo Alto Negate Object Meaning

Hi,

 

I have a question on Palo Alto negate object. If I have a allow rule that allow src zone A, src IP of 10.10.10.0/24 (Negate) to dst zone B, dest IP of ANY.

 

Does it mean that the rule is allowing other src IP (not including 10.10.10.0/24) from src

...

Risk 0 for workday and service now.

Hi, 

I noticed in our ACC dashborad that the applicaitons in use such as workday and servicenow were assigned a risk of 0.  Is that becuase they have not been identified as risky apps or thats the lowest risk level which means no threat app.  

 

Thank y

...

TCP SYN with data Threat logs

Hi Guys,

 

I receive hundreds of TCP SYN with data Threat Alerts from my BYOD zone every day. I was learning more about it and I understood that it is a TCP syn packet with data in its payload. However, as almost all of them seems to come from non-mali

...

Resolved! Dynamic IP List import now failed

I just have the two default PA dynamic IP lists, but they each only have roughly 100 IPs.  I would think there would be more than that but when I try to hit 'import now' it just fails.  Anyone shed some light on how these two lists work and how often

...

drewdown by L4 Transporter
  • 22476 Views
  • 15 replies
  • 0 Likes
  • 511 Posts
  • 71 Subscriptions
Top Liked Authors