Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
About Threat & Vulnerability Discussions

Welcome to the Threat and Vulnerability discussion forum. This forum exists as a resource for security professionals to discuss and share information pertaining to the topics of threats and vulnerabilities.
Not a LIVEcommunity member? Simply click here and register!

Discussions

Resolved! File Blocking - .exe vs .exe

I was testing file blocking before implementation and .exe does not get entirely blocked. 2 different exe files, one from microsoft does not get blocked while another from nirsoft gets blocked. Is there a difference to what kind of exe files get bloc

...

raji_toor by L4 Transporter
  • 12154 Views
  • 4 replies
  • 0 Likes

DNSProxy - Resolve-Fail - cpsc.gov

Warning: very new to PANOS.

 

I'm seeing a TON of these messages, to the tune of about 2-300 per second in my system log: Failed to resolve domain name: cpsc.gov after trying all attempts to name server(s): mynameserverinternalip.

 

I've read that this d

...

HavisIT by L0 Member
  • 4674 Views
  • 0 replies
  • 5 Likes

Flurry of Ramnit Detections

Around 04:00-05:00 yesterday my users triggered a series of ramnit detections which were blocked, but when I looked at the logs  it seems a bit unclear.  The threat logs are reporting that the file postprocess.dll carried the malware, but tying the U

...

djr by L4 Transporter
  • 3253 Views
  • 0 replies
  • 0 Likes

Office 365 - Poodle Vunerabilties

Threat ID - 37144 

 

Question or insight about Microsoft practices with not hardening against poodle.

 

Why am I still getting alerts for these vulnerabilities, is it because I don't have proper SSL forward proxy yet enabled? Or is it because my Office 3

...

CZaloba by L0 Member
  • 3344 Views
  • 0 replies
  • 0 Likes

ACC risk factor

Looking at our ACC tab, I see that SMTP traffic has a risk of 5.  We only accept SMTP from our Symantec.cloud smart host.  It is then decrypted coming into our firewall and scanned again.  We do not decrypt outgoing SMTP, but we do have an anti-virus

...

Resolved! Cascading URL Filters?

To the world, creating Security rule for a specific user (call it, a rule to permit access dodgy website access), what's involved in "cascading" the rule - so, if there's no matches on that rule, that same user would be challenged against a General W

...

  • 516 Posts
  • 71 Subscriptions
Top Liked Authors