Modify the Advanced WildFire compressed file level inspection on Prisma
Access.
Attackers frequently hide malicious payloads deep within nested compressed files to
evade standard security scanning tools that only inspect initial layers. To combat
this evasive technique and strengthen your protection against advanced threats, the
ability to inspect deeply compressed content has been expanded to include Prisma
Access.
Because enabling higher compression depths can significantly impact performance,
adjustments to the default depth should be closely monitored to ensure system
stability. If your security requirements necessitate increasing the decoding depth
beyond the default four levels, Palo Alto Networks recommends incrementally
increasing the compressed file level inspection, starting with the minimum value
that meets the security requirements for inspecting compressed files.
Update:
Firewall support added in PAN-OS 11.0.
Prisma Access support added in the Prisma Access 6.1.0 release.
To enable configuration for compressed file level inspection; reach out to your
Palo Alto Networks account team.