Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
About Threat & Vulnerability Discussions

Welcome to the Threat and Vulnerability discussion forum. This forum exists as a resource for security professionals to discuss and share information pertaining to the topics of threats and vulnerabilities.
Not a LIVEcommunity member? Simply click here and register!

Discussions

Cortex XDR - Coyote Trojan

Hi,


Does anyone know that Cortex XDR can detect and prevent Coyote Trojan as described by Kaspersky? https://securelist.com/coyote-multi-stage-banking-trojan/111846/

 

Appreciate any feedback. Thank you.

 

Therry by L1 Bithead
  • 1284 Views
  • 1 replies
  • 0 Likes

SSH Brute Force

Client connects to FTP server via SSH and starts downloading. After a while, connection stops. I see in the logs that there a multiple SSH login attempts and finally SSH Brute Force with reset-both action. 

What would be the reason?

HyAz45 by L0 Member
  • 1613 Views
  • 1 replies
  • 0 Likes

Resolved! false positive 626399763

https://download.visualstudio.microsoft.com/download/pr/4526499f-1262-4419-a3d2-66d1e32d18da/212c3a4edab3d8e5f5c2e38bc3d51378c9f7a4eb64409b4e2b0918dc70d0d176/Microsoft.VisualStudio.Web.Scaffolding.vsix is regarded as a virus by our firewall. Content-

...

halladm by L0 Member
  • 2411 Views
  • 1 replies
  • 0 Likes

Suspicious User-Agent Strings

Hi All,

 

I have noticed a log from our Palo Alto vulnerability report that looks suspicious yet I am unaware of it.

There is a threat "Suspicious User-Agent Strings" detected under the "spyware" category and "HTTP-proxy" application from Globalprote

...

Jerome.j by L1 Bithead
  • 2658 Views
  • 1 replies
  • 0 Likes

Text injection issue on firewall

Dear Team ,

 

We have a customer he is facing issue with , Text injection is enabled on firewall portal web application.

We noticed a problem with the Palo Alto web portal is getting affected by text injection during the security audit. We must mitig

...

Student extensive use of VPNs.

Hello Livecommunity. We are in a bind. We have numerous students on our school networks that are bypassing security profile rules with VPNs. So frustrating. I do have rulesets that look for annnomizers and proxies. I also have explicit rules that loo

...

JCMoritz by L1 Bithead
  • 5341 Views
  • 4 replies
  • 0 Likes
  • 509 Posts
  • 69 Subscriptions
Top Solution Authors
Top Liked Authors