The Indicators tab provides a summary of threat intelligence data that Palo Alto Networks has on a particular threat indicator — URLs, domains, IP addresses (IPv4 and IPv6), and hashes. The threat intelligence summary data, depending on the type of indicator, can include the WildFire verdict, detection reasons, associated metadata (including the indicator source(s)), WHOIS information, tags, logs of DNS activity from all samples analyzed with WildFire, active/passive DNS history where AutoFocus detected instances of the artifact, and other related information. This can help you assess whether a specific hash, domain, URL, or IP address is associated with suspicious behavior and analyze the nature of a threat.
Indicators List Details
Threat Indicator Overview
The threat indicator summary provides a breakdown of the properties, behaviors, and activities reported by various Palo Alto Networks analytics services. URL entries can include additional context provided by analysis data derived from the improved URL analysis capabilities found in the WildFire global cloud. This content is categorized into three categories: Summary, Evidence, and Analyst. The summary provides a high level overview of the URL, including PAN-DB categorization details, detection reasons with verdict, Whois information, accompanied by a screenshot. Evidence shows details regarding why and how the verdict was reached. Analyst describes various insights into the operational details of the web page, including network traffic and file transfers. For all other indicators, the threat indicator summary provides a breakdown of the general properties, behaviors, and activities reported by various Palo Alto Networks analytics services.The following list shows some of the threat data that can populate the threat indicator overview.
A direct link to the VirusTotal analysis of the specified file hash.
This options is only available for file hashes.
Sample and Session Details
You can pivot to a sample or session search on the specified indicator. This automatically initiates a search based off of the initial query and can provide a wider context and additional details.
Recommended For You
Recommended videos not found.