Indicators
Table of Contents
Expand all | Collapse all
Indicators
The Indicators tab provides a summary of threat intelligence
data that Palo Alto Networks has on a particular threat indicator
— URLs, domains, IP addresses (IPv4 and IPv6), and hashes. The threat
intelligence summary data, depending on the type of indicator, can
include the WildFire verdict, detection reasons, associated metadata
(including the indicator source(s)), WHOIS information, tags, logs
of DNS activity from all samples analyzed with WildFire, active/passive
DNS history where AutoFocus detected instances of the artifact,
and other related information. This can help you assess whether
a specific hash, domain, URL, or IP address is associated with suspicious
behavior and analyze the nature of a threat.
Indicators
List Details | |
---|---|
The threat indicator summary provides a
breakdown of the properties, behaviors, and activities reported
by various Palo Alto Networks analytics services. URL entries can
include additional context provided by analysis data derived from
the improved URL analysis capabilities found in the WildFire global
cloud. This content is categorized into three categories: Summary,
Evidence, and Analyst. The summary provides a high level overview
of the URL, including PAN-DB categorization details, detection reasons
with verdict, Whois information, accompanied by a screenshot. Evidence
shows details regarding why and how the verdict was reached. Analyst
describes various insights into the operational details of the web
page, including network traffic and file transfers. For all other
indicators, the threat indicator summary provides a breakdown of
the general properties, behaviors, and activities reported by various
Palo Alto Networks analytics services.The following list shows some
of the threat data that can populate the threat indicator overview.
| |
A direct link to the VirusTotal analysis
of the specified file hash. This options is only available
for file hashes. | |
You can pivot to a sample or session search
on the specified indicator. This automatically initiates a search
based off of the initial query and can provide a wider context and
additional details. |