User Tools

Site Tools


paloaltonetworks:troubleshooting:testing_panos

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
paloaltonetworks:troubleshooting:testing_panos [2023/01/21 16:42] – [DNS Security] bstaffordpaloaltonetworks:troubleshooting:testing_panos [2023/01/21 16:54] (current) – [DNS Security] bstafford
Line 43: Line 43:
  
 To find example malicious domains, look in the release notes of the active AV file on the firewall (Setup > Dynamic Updates). Search for <code>New Spyware DNS C2 Signatures</code> To find example malicious domains, look in the release notes of the active AV file on the firewall (Setup > Dynamic Updates). Search for <code>New Spyware DNS C2 Signatures</code>
 +
 +In built AV file based DNS malware detection:
 +<code>( name-of-threatid contains 'Suspicious DNS Query (Compromised_DNS' )
 +( name-of-threatid contains 'Suspicious DNS Query (generic' )</code>
  
  
paloaltonetworks/troubleshooting/testing_panos.1674319342.txt.gz · Last modified: by bstafford