Hi, wildfire post detection means that in first step the local analysis of the client has flagged the executable/macro/DLL as benign. In parallel the file is uploaded to wf and analysed by static analysis and dynamic one. Afterwards the wildfire verdict is malware for your file. ESM gets the verdict and creates this wildfire post detection event, because the local analysis verdict (benign) from the endpoint is changed to malware (wf verdict). So if this is your intial run of this file and you are running on prevention mode, the file would have been executed on the client. After the wf verdict is available on the esm, further execusions would be blocked. In your case it does not matter, because you have applied a notification rule, so every file can be executed independently of the verdict. To point 3: I would say, you are right. Maybe paloalto engineer or pan support can give you deeper information. I hope that helps you. BR, Jan
... View more