WildFire reproduces a variety of analysis environments, including the operating system, to identify malicious behaviors within samples. Depending on the characteristics and features of the sample, multiple analysis environments may be used to determine the nature of the file. WildFire uses static analysis with machine learning to initially determine if known and variants of known samples are malicious. Based on the initial verdict of the submission, WildFire sends the unknown samples to analysis environment(s) to inspect the file in greater detail by extracting additional information and indicators from dynamic analysis. If the file has been obfuscated using custom or open source methods, the WildFire cloud decompresses and decrypts the file in-memory within the dynamic analysis environment before analyzing it using static analysis. During dynamic analysis, WildFire observes the file as it would behave when executed within client systems and looks for various signs of malicious activities, such as changes to browser security settings, injection of code into other processes, modification of files in operating system folders, or attempts by the sample to access malicious domains. Additionally, PCAPs generated during dynamic analysis in the WildFire cloud undergo deep inspection and are used to create network activity profiles. Network traffic profiles can detect known malware and previously unknown malware using a one-to-many profile match.
WildFire analyzes files using the following methods:
- Static Analysis—Detects known threats by analyzing the characteristics of samples prior to execution.
- Machine Learning—Identifies variants of known threats by comparing malware feature sets against a dynamically updated classification systems.
- Dynamic Unpacking (WildFire Cloud analysis only)—Identifies and unpacks files that have been encrypted using custom/open source methods and prepares it for static analysis.
- Dynamic Analysis—A custom built, evasion resistant virtual environment in which previously unknown submissions are detonated to determine real-world effects and behavior.
- Bare Metal Analysis (WildFire Cloud analysis only)—A fully hardware-based analysis environment specifically designed for advanced VM-aware threats. Samples that display the characteristics of an advanced VM-aware threat are steered towards the bare metal appliance by the heuristic engine.
WildFire operates analysis environments that replicate the following operating systems:
- Microsoft Windows XP 32-bit
- Microsoft Windows 7 64-bit
- Microsoft Windows 7 32-bit (Supported as an option for WildFire appliance only)
- Microsoft Windows 10 64-bit (WildFire Cloud Analysis only)
- Mac OSX (WildFire Cloud Analysis only)
- Android (WildFire Cloud Analysis only)
- Linux (WildFire Cloud Analysis only)
The WildFire public cloud also analyzes files using multiple versions of software to accurately identify malware that target specific versions of client applications. The WildFire private cloud does not support multi-version analysis, and does not analyze application-specific files across multiple versions.
WildFire Analysis Reports—Close Up
WildFire Analysis Reports—Close Up Access WildFire analysis reports on the firewall , the WildFire portal , and the WildFire API . WildFire analysis reports display ...
Get WildFire Information through the WildFire API
Get WildFire Information through the WildFire API The WildFire™ API lets you programmatically retrieve WildFire verdicts, samples, packet captures (PCAPs), and WildFire analysis reports. You ...
WildFire Concepts Samples Firewall Forwarding Session Information Sharing Analysis Environment Verdicts File Analysis Email Link Analysis Compressed and Encoded File Analysis WildFire Signatures WildFire Example ...
WildFire Global Cloud
WildFire Global Cloud A Palo Alto Networks firewall with can forward unknown files and email links to the WildFire global cloud or to one of ...
WildFire File Type Support
WildFire File Type Support The following table lists the file types that are supported for analysis in the WildFire cloud environments. File Types Supported for ...
Forward Files for WildFire Analysis
Forward Files for WildFire Analysis Configure Palo Alto Networks firewalls to forward unknown files or email links and blocked files that match existing antivirus signatures ...
About WildFire The WildFire Analysis Environment identifies previously unknown malware and generates signatures that Palo Alto Networks firewalls can use to then detect and block ...
WildFire Subscription The basic WildFire service is included as part of the Palo Alto Networks next generation firewall and does not require a WildFire subscription. ...
Get a Packet Capture (WildFire API)
Get a Packet Capture (WildFire API) Use this resource to request a packet capture (PCAP) recorded during analysis of a particular sample. Use either the ...