Security LifeCycle Review Flagging Unknown Binary as High Risk FileTypes

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Security LifeCycle Review Flagging Unknown Binary as High Risk FileTypes

L0 Member

Hello All,

Can anybody in the group share their experience/Knowledge over Unknown binaries? As I am observing my Security control flagging Unknown Binaries as a High-Risk filetype. I just need to know what actually these unknown binaries are ? for what they are used for ? what are their potential threats/risk to organizations infrastructure ? and what are the possible detection and prevention methods could be deployed or used against them?

 

I have been researching a lot but unable to find something convincing answers to my concerns and also want to have words from professionals here.

If someone ever encountered with Unknown Binaries are requested to kindly share their knowledge here.

Thank you! 

1 REPLY 1

L4 Transporter

Hello @Daniyal 

 

Beginning with the content release version 8215, Palo Alto Networks added a new file type, "unknown-binary," for customers running a PAN-OS 9.0 release. This new file type enables visibility for files that are binary encoded and not identified as any other supported file type. For customers who want visibility into transfers of "unknown-binary" files in their networks, we recommend that you set this file type to "alert" so that you can observe where these files appear in your network traffic. We also recommend that you monitor your Data Filtering logs for "Unknown Binary File" for several weeks before you consider updating to a more severe action ("block" or "continue"). If you are running a PAN-OS 9.0 release with an "alert all" rule in your file-blocking profiles (which includes the predefined "basic file blocking" and "strict file blocking" profiles), expect to see logs for "Unknown Binary File" after you install this content update; additionally, you can configure the "unknown-binary" file type in File Blocking profiles. (Customers running a PAN-OS 8.1 or earlier release will not experience any changes related to this new file type.)

 

Thank you

Himani

Himani Singh
  • 4378 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!