WildFire Report Incorrect Verdict (virus false positive or false negative)

WildFire Report Incorrect Verdict (virus false positive or false negative)

36330
Created On 09/27/18 06:50 AM - Last Modified 06/23/21 17:34 PM


Symptom
  • False Positive or False Negative received for Wildfire Sample


Environment
  • WildFire services enabled


Resolution

You can quickly report these without opening a Support Cases from methods below:

 


Submit from the WildFire Portal


submit request via WildFire portal
 
  1. Go to the WildFire portal you are using: Global, CA, EU, UK, JP, or AU
  2. Find the sample you wanted to change verdict for and click on the details so you can access the WildFire report
  3. Scroll down to the bottom of the page to follow the link to report an incorrect verdict
  4. Fill in the Verdict Change Request with a suggestion of a new verdict, your contact email, and a short explanation why you believe this verdict is incorrect. After the manual review is completed, a report will be sent to the email address you used here.
 


Submit from Panorama and Firewall

submit request via Panorama or Firewall
  1. Log into Panorama or Firewall, and go to Monitor > WildFire Submissions
  2. Find the file for which you want to change verdict and click on the icon to open detailed log view 
  3. Scroll down to the bottom of the WildFire Analysis Report and click “report an incorrect verdict” to find a new pop-up window
  4. Fill in the Verdict Change Request with a suggestion of a new verdict, your contact email, and a short explanation why you believe this verdict is incorrect. After the manual review is completed, a report will be sent to the email address you used here.
 


Submit from Cortex XDR

submit request via Cortex XDR portal
  1. Log into Cortex XDR; in the Incident with a wrong verdict for a sample
  2. Open detailed WildFire Analysis Report for the sample with the wrong verdict,
  3. Use a button “Report Verdict as Incorrect” to open a new menu
  4. Fill in the Verdict Change Request with a suggestion of a new verdict, your contact email, and a short explanation why you believe this verdict is incorrect. After the manual review is completed, a report will be sent to the email address you used here.
 


Submit from the WildFire Report PDF
(without WildFire Portal Access)

WildFire PDF Report
  1. Open the report and look for “Report to Palo Alto Networks at the bottom of the report
  2. Fill in the Verdict Change Request with a suggestion of a new verdict, your contact email, and a short explanation why you believe this verdict is incorrect. After the manual review is completed, a report will be sent to the email address you used here.


Additional Information
How To Provide Evidence Of An Incorrect WildFire Verdict From VirusTotal

Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm7KCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Attachments
Choose Language