Error:
An unexpected error occurred. Please click Reload to try again.
Error:
An unexpected error occurred. Please click Reload to try again.
Searching Threat IDs, Signatures and other Indicators on Threat... - Knowledge Base - Palo Alto Networks

Searching Threat IDs, Signatures and other Indicators on Threat Vault

207110
Created On 12/02/19 20:05 PM - Last Modified 10/15/24 12:26 PM


Objective


Research the latest threats (vulnerabilities/exploits, viruses, and spyware) that Palo Alto Networks next-generation firewalls can detect and prevent

Note: Need have a valid support account


Environment


  • ThreatVault


Procedure


You can search Threat Vault for most types of indicators.  To start, navigate to Threat Vault using the link - https://threatvault.paloaltonetworks.com/
You can also search by indicators like Hash, CVE numbers, Signature ID, and Domain name as indicated below.

Example of how the Threat Vault page looks

Threat Vault contains the following information:

  • Anti-spyware Signatures
  • Antivirus Signatures
  • DNS Signatures
  • File-format signatures
  • IP Feed
  • PAN-DB URL Classifications
  • Vulnerability Protection Signatures
  • WildFire Signatures

 

Threat Vault also has an API. The Threat Vault API provides Palo Alto Networks customers with an active Advanced Threat Prevention or Threat Prevention subscription with the ability to access threat signature metadata and other pertinent information that's only available in Threat Vault, through a programmatic RESTful API.

Before using the Threat Vault API, please refer to Cloud-Delivered Security Services API Developer's docs for more information about using the API, including authentication details, access limits, and examples.

 



Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNhzCAG&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language