Threat & Vulnerability
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
511 PostsThis forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
511 PostsTraps Advanced Endpoint Protection prevents cyber breaches by protecting and enabling users to conduct their daily activities, and automating prevention by autonomously reprogramming itself using threat intelligence gained from WildFire.
20 PostsA forum to ask or share about Data Loss Prevention (DLP) strategy. DLP ensures sensitive or confidential information doesn't leak outside of the corporate network. Let's rethink DPL together.
12 PostsThis forum is to discuss Palo Alto Networks' Next-Generation CASB, an integrated, multi-faceted CASB solution that helps security teams meet the security challenges of today.
13 PostsDiscussions about IoT Security — aka the Internet of Things — a cybersecurity strategy that safeguards against the possibility of cyberattacks which specifically target physical IoT devices that are connected to the network.
24 PostsWelcome to the AI Access Security discussion area! Here, we focus on how AI Access Security facilitates safe Generative AI adoption by providing real-time visibility, streamlined access control, and robust data protection. Join us to share insights and discuss strategies for keeping sensitive information secure in AI applications.
2 Posts
Hi I would like to enquire if any Palo Alto products are affected by the above vulnerability.
Thanks.
I looking for the log file that tracks the IP addresses of devices that have connected to our Palo Alto Networks firewall.
I am interested in any logs that show source and destination IP addresses for network connections.
Could you please point me to
...
Hello
I'm Tomoyuki Nakamura.
Are there any plans to release signature for the vulnerabilities below?.
These were not listed in THREAT VAULT or Security Advisory.
CVE-2024-8932
CVE-2024-11236
Best Regards,
Tomoyuki Nakamura
In Prisma cloud how do i track base images. that is the know who is using the defined base images and who is not using them. like can i get a list of all containers leveraging the defined base images?
Hi Everyone,
I am currently setting up Cortex XDR to run alongside a parallel EDR solution and want to ensure proper exclusions are configured to avoid conflicts and performance issues.
Could anyone share the recommended file and folder exclusions sp
...
Dear experts,
Here is my question:
Our customer has registered new URL domains and configured the firewall to block all newly registered domains via the URL filtering configuration. They noticed that the new domain is NOT blocked right away but abo
...
Hi Team,
Just one of our customer received an security query points where they wanted the firewall to block reverse TCP shells and other potential backdoor connections.
For backdoor i have went through the backdoor signatures in threat vault.
So we ha
...
It is suggested to upgrade to version 10.2.12-h2 to remediate the vulnerability. However, the firmware version 10.2.12-h2 is currently in monitoring status. It is also mentioned that the same fix is available in version 10.2.10-h9, which is the prefe
...
We cannot update Adobe Creative cloud when on our network or Global protect. What I'm seeing is in the Threat logs for adobe-creative-cloud-base threat ID 678983911, content version Antivirus-4995-5513,
ccmdls.adobe.com/AdobeProducts/KCCC/1/win64
...
Good morning,
I would like to know if there is a way to leave a field blank when editing an asset. For example, when I change the information of an asset that has been detected wrongly, it does not allow me to leave the OS Family section blank. Is the
Hello,
Please fix false positive detection:
https://www.virustotal.com/gui/file/5259f523e41ffa42af0753df4c020f911a585b311c3267f17703c14920a352b8?nocache=1
Thank you!
Hi,
After the update PA to version 11.1.0 (currently we are using version 11.1.1 but the problem still exists), Nessus discovered open TCP port 9339 and alerted about vulnerability SWEET32 (screen attached below).
It is weird, because port 9339 is u
...
didn't received any incident alert logs from cortex xdr agent to cortex manager.
using cortex broker version 25.0.44 and cortex agent version 8.5
Hello,
I was wondering, is it possible to customize out of the box Cortex XDR notifications?
They are good and informative, but I would like to see tenant name in incident e-mail notification.
My work involves multiple tenants, and when I receive incide
User | Likes Count |
---|---|
2 | |
1 | |
1 | |
1 |