Security LifeCycle Review Flagging Unknown Binary as High Risk FileTypes

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L0 Member

Security LifeCycle Review Flagging Unknown Binary as High Risk FileTypes

Hello All,

Can anybody in the group share their experience/Knowledge over Unknown binaries? As I am observing my Security control flagging Unknown Binaries as a High-Risk filetype. I just need to know what actually these unknown binaries are ? for what they are used for ? what are their potential threats/risk to organizations infrastructure ? and what are the possible detection and prevention methods could be deployed or used against them?

 

I have been researching a lot but unable to find something convincing answers to my concerns and also want to have words from professionals here.

If someone ever encountered with Unknown Binaries are requested to kindly share their knowledge here.

Thank you! 

Highlighted
L4 Transporter

Hello @Daniyal 

 

Beginning with the content release version 8215, Palo Alto Networks added a new file type, "unknown-binary," for customers running a PAN-OS 9.0 release. This new file type enables visibility for files that are binary encoded and not identified as any other supported file type. For customers who want visibility into transfers of "unknown-binary" files in their networks, we recommend that you set this file type to "alert" so that you can observe where these files appear in your network traffic. We also recommend that you monitor your Data Filtering logs for "Unknown Binary File" for several weeks before you consider updating to a more severe action ("block" or "continue"). If you are running a PAN-OS 9.0 release with an "alert all" rule in your file-blocking profiles (which includes the predefined "basic file blocking" and "strict file blocking" profiles), expect to see logs for "Unknown Binary File" after you install this content update; additionally, you can configure the "unknown-binary" file type in File Blocking profiles. (Customers running a PAN-OS 8.1 or earlier release will not experience any changes related to this new file type.)

 

Thank you

Himani

Himani Singh
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!