Thanks for thta information. How about adding MD5 hash (whole file) to Palo? I can see some of our hashes were already covered with built in Palo threatvault database but someone of them are not. Since Plao checking the file hash and compare its mailcious hash database, can I add my own hashes along with Palo predefined one? Is there any way to add our custom hashes to Plao? We have over 3000 hashes from previous IPS devices and it's not easy to check every one of them through threatvalut by manual process. Also, I would prefer not to hand-jam 400 snort signatures, but if we do, we would like to ensure that we are creating the new signatures properly so any help with conversion process and document to creating them would be appreciated. Thanks
... View more