Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Threat & Vulnerability Discussions
This forum provides information regarding how to detect and prevent the impact of vulnerabilities, malware, and other threats through the use of the Palo Alto Networks security platform.
About Threat & Vulnerability Discussions

Welcome to the Threat and Vulnerability discussion forum. This forum exists as a resource for security professionals to discuss and share information pertaining to the topics of threats and vulnerabilities.
Not a LIVEcommunity member? Simply click here and register!

Discussions

Resolved! Spyware Detections

Hi Community,

 

Lately we are noticing on one of our clients environment where PA is flagging traffic to "mail.google.com" as Spyware. The captured signature is "sliver framework command and control traffic detection".

 

I did run the captured URL "m

...

Resolved! dns sinkhole rule

hi all

 

 

we are in a dilemma, we have enable dns sinkhole in our anti-spyware profile enable:

dns sinkhole > DNS Policies > default-paloalto-dns > sinkhole enable .

DNS Sinkhole Setting> IPv4 > X.X.X.X

Now, this profile is also added to our securit

...

Resolved! Blocking Scammer website (cryptocurrency)

I stumbled accros this article on Bleeping Computers

https://www.bleepingcomputer.com/news/security/tiktok-flooded-by-elon-musk-cryptocurrency-giveaway-scams/

To my surprise the URL's mentioned in the article where considered safe. 

Palo Alto had the

...

Remko by L1 Bithead
  • 5498 Views
  • 7 replies
  • 0 Likes

Cortex XDR Remote account enumeration

Hello,

today we have interesting alert

 

At least 33 distinct non-existing accounts failed to remotely log in to XX-Laptop1. Users list: name.user, user name, user.name, username

 

User has no idea - all day at school, behind NAT. What I cannot reall

...

LukasB_0-1663265938108.png
LukasB_1-1663266012645.png
LukasB by L2 Linker
  • 3336 Views
  • 3 replies
  • 1 Likes

out of date CVEs

I am curious about the listing of vulnerabilities in the vulnerabilities assessment.  It seems like it is catching old out dated CVE's and attaching them to fully updated machines.  for example i have numerous machines showing a vulnerability CVE-202

...

Apps and Threats Mismatch

Hi All

 

I have a pair of Panorama managed Firewalls configured in a HA Setup . However I m observing a mismatch on the App and Threat versions across both devices . Although the "Synch To Peer" option is enabled on the App and Threat schedule settin

...

Passive-AppandThreat.jpg
Active-AppandThreat.jpg
File2.jpg
File1.jpg

Vulnerability Protection Profile

Hello!

 

I have a rule with a vulnerability protection profile enabled between my VPN users and DMZ.

I need to WebGUI (8443/8080) into a new DMZ server, but VP is stopping it.

How do I make an exception for this traffic?

 

Thanks,

DC

DCleve by L0 Member
  • 1755 Views
  • 3 replies
  • 0 Likes
  • 494 Posts
  • 63 Subscriptions
Top Liked Authors