: Advanced WildFire Support for EML Files
Focus
Focus

Advanced WildFire Support for EML Files

Table of Contents

Advanced WildFire Support for EML Files

The Advanced WildFire cloud now supports forwarding, analysis, and prevention of threats contained in EML (email message) files.
To enable forwarding of eml files from the firewall, be sure to download and install the latest PAN-OS content release. PAN-OS Applications and Threats content release 8969 allows firewalls operating PAN-OS 11.1.0 and later to forward eml files to the Advanced WildFire cloud for analysis. For more information about the update, refer to the Applications and Threat Content Release Notes.
To download the release notes, log in to the Palo Alto Networks Support Portal, click Dynamic Updates and select the release notes listed under Apps + Threats.
Palo Alto Networks® WildFire® now supports forwarding, analysis, and prevention of threats contained in email message files (EML). EML files are used to store email message contents and typically includes the entirety of a single email in plain text format. Because this includes all contents of the email (including the email headers, message body, attachments, and other MIME components), any malicious contents that can be delivered using those vectors are analyzed by the Advanced WildFire cloud for threats.
When a malicious file is discovered, the Advanced WildFire cloud generates and distributes protections to prevent future successful attacks. To ensure that you are protected from the latest threats, always download and install the latest content and software updates from Palo Alto Networks.
To forward EML files for analysis, the WildFire Analysis Profile must be configured to forward the eml file type. You can also select any Any to forward all supported unknown files to the Advanced WildFire cloud for analysis.