Docuemento Tecnico WF
Docuemento Tecnico WF
Docuemento Tecnico WF
Industry sharing
SaaS Partner
Cortex integrations
WF • Prioritized events
• Contextual threat
Static Analysis
• Proactive response
Cloud-based • Correlated third-
threat intelligence Dynamic Analysis party threat feeds
• Granular and
custom tags
• Custom alerts
Bare Metal Analysis • Trend reports
• AutoFocus™ contextual threat intelligence service, en- • Suspicious network traffic analysis monitors all network
abling the extraction, correlation, and analysis of threat activity produced by the suspicious file, including back-
intelligence with high relevance and context. door creation, downloading of next-stage malware, vis-
iting low-reputation domains, network reconnaissance,
• Cortex XDR™ agent and Prisma™ SaaS for realtime verdict
and much more.
determination and threat prevention.
• Anti-analysis detection monitors advanced malware
• Integration with our technology partners for verdict deter-
techniques designed to avoid VM-based analysis, such as
mination on third-party services with the WildFire API.
debugger detection, hypervisor detection, code injection
into trusted processes, disabling of host-based security
Most Advanced Malware Analysis features, and much more.
In combination with WildFire, organizations can use
AutoFocus to home in on the most targeted threats with high
WildFire brings forth years of groundbreaking innovation to relevance and context. AutoFocus provides the ability to hunt
provide the most advanced analysis environment in the in- across all data extracted from WildFire, as well as third-
dustry, enabling the most accurate and evasion-resistant party threat feeds, using MineMeld™ threat intelligence
detection of unknown threats available today. The WildFire syndication engine. It allows users to correlate i ndicators of
engine is based on two primary components. compromise and samples with human intelligence from the
Unit 42 threat research team in the form of tags. Together,
Custom-Built Hypervisor WildFire and AutoFocus provide a complete picture of un-
Built from the ground up to avoid use of commonly used, open known threats targeting your organization and industry, in-
source emulation software that has become trivial to evade, the creasing your ability to quickly take action by:
WildFire hypervisor is immune to commoditized anti-VM anal- • Automatically updating External Dynamic Lists on Palo
ysis techniques used to evade detection in traditional malware Alto Networks Next-Generation Firewalls.
analysis environments. The custom hypervisor also provides • Automatically exporting indicators of compromise to
a flexible framework to continue building advanced detection third-party tools via STIX™, TAXII™, and APIs.
and evasion-resistant capability into WildFire in the future.
These actions require no human intervention and reduce the
Bare Metal Analysis cost of adding specialized security staff.
i ntelligence extraction, and protection generation, • An open API for integration with third-party security
but it maintains the ability to receive updates from the tools, such as security information and event management
global cloud for customers with privacy or regulatory systems (SIEMs).
• Hybrid cloud delivery: You can combine the benefits of the
global and private clouds by choosing to send sensitive files Security Operating Platform
to the private cloud while other content is analyzed by the Built on the Security Operating Platform®, WildFire blocks
global cloud. known and unknown threats before they can cause harm, tak-
• Global cloud infrastructure: Take advantage of automated ing advantage of:
protections delivered through the global cloud without the • Full visibility into all network traffic activity, including
need to send content beyond your borders, allowing you to stealthy attempts to evade detection, such as the use of
maintain privacy and compliance at scale. nonstandard ports or SSL encryption.
• Attack surface reduction with positive security controls to
Integrated Logging, Reporting, proactively take away infection vectors.
and Forensics
• Automatic known threat prevention with our Next-
Generation Firewalls, Threat Prevention, URL Filtering,
WildFire users receive integrated logs, analysis, and visi- Cortex XDR agents, and Prisma SaaS, providing defenses
bility into malicious events through the PAN-OS® manage- against known exploits, malware, malicious URLs, and
ment interface, Panorama™ network security management, command-and-control activity.
AutoFocus, or the WildFire portal, enabling teams to quickly • Unknown threat detection and prevention with WildFire,
investigate and correlate events observed in their networks. including threat analytics with high relevance and context
This allows security staff to rapidly locate and take action through the AutoFocus service.
on the data needed for timely investigations and incident The result is a unique, closed-loop approach to preventing
response, including: cyberthreats, ensuring they are known to all and blocked
• Detailed analysis of every malicious file sent to WildFire across the attack lifecycle.
across multiple operating system environments, including
both host- and network-based activity.
• Session data associated with the delivery of the malicious Maintaining the Privacy of Your
file, including source, destination, application, user, URL, Files
and other attributes.
The security and privacy of customer data is our top priority.
• Access to the original malware sample for reverse engi-
The WildFire infrastructure is managed directly by Palo Alto
neering, with full PCAPs of dynamic analysis sessions.
Networks, leverages industry-standard best practices for
3000 Tannery Way © 2020 Palo Alto Networks, Inc. Palo Alto Networks is a registered
Santa Clara, CA 95054 trademark of Palo Alto Networks. A list of our trademarks can be found at All other
Main: +1.408.753.4000 marks mentioned herein may be trademarks of their respective companies.
Sales: +1.866.320.4788 wildfire-ds-021320
Support: +1.866.898.9087