Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
About Threat & Vulnerability Discussions

Welcome to the Threat and Vulnerability discussion forum. This forum exists as a resource for security professionals to discuss and share information pertaining to the topics of threats and vulnerabilities.
Not a LIVEcommunity member? Simply click here and register!

Discussions

policy, objects and smtp

howdy,

I can not get my head around how to do this.

Allow smtp from a country but block every other service, application.

You can negate countries but not services/applications.

can one do any/any with an exception?

Thank you

PA200-1 by L1 Bithead
  • 2046 Views
  • 3 replies
  • 1 Likes

How to Block RClone

If I search for rclone in the applications on my PAN 3220 w 9.1, I am not spotting "rclone". 
Is there a means of identifying and blocking rclone traffic?

 

https://research.nccgroup.com/2021/05/27/detecting-rclone-an-effective-tool-for-exfiltration/

palomed by L3 Networker
  • 1895 Views
  • 0 replies
  • 1 Likes

PoshC2 false positive

Hello,

We are seeing what appears to be false positive detections for the PoshC2C vulnerability signatures that was released recently. Connections going to Google and BBC, is anyone else seeing the same thing here?

Block on APP-ID (Apache Log4j )

Hello All,

After a bit of help ...I' have never created a block type rule on a Palo and now my boss wants me to create a .block rule for the above.

We have about 300 policies in the our firewall so no idea how to create a block and apply it .

Can anybod

...

Scott64 by L1 Bithead
  • 3438 Views
  • 3 replies
  • 1 Likes
  • 488 Posts
  • 63 Subscriptions
Top Solution Authors
Top Liked Authors