Organizations operate globally and frequently adhere to strict regional data
compliance requirements when Advanced WildFire® is deployed into corporate networks
for malware analysis. When using dynamic analysis for MacOSX files, meeting these
geographic mandates can present a challenge. To address this control gap,
the Advanced WildFire® service now provides the
ability to choose the geographic location where MacOSX files are forwarded to
for Advanced WildFire dynamic analysis. This ensures that customers
maintain precise governance over where their samples are analyzed. This feature
allows administrators to designate specific regional WildFire clouds—currently those
located in the US, EU, Singapore, or Japan—to analyze and classify MacOSX files with
WildFire verdicts using dynamic analysis, a high-fidelity sandboxing solution that
tests the suspected file in a secure, virtualized environment to observe its
behavior. The sample is temporarily sent to the region designated for MacOSX dynamic
analysis, during which the file is analyzed and subsequently deleted. The sample
analysis results are then sent to your configured WildFire public cloud region for
access. The Advanced WildFire cloud uses the sample analysis results to generate and
distribute signatures used by various Palo Alto Networks products to prevent further
distribution of malicious threats contained in MacOSX files. By enforcing strict
geographic boundaries for analysis, organizations can balance robust threat
detection with regional data residency mandates. For maximum security, the
forwarding functionality is disabled by default, ensuring configuration requires
deliberate authorization. This capability strengthens compliance posture while
leveraging the full detection power of Advanced WildFire.