What is the target release version / target release date of a signature?
Question
- I heard the target release week of a new signature / the fix of an existing signature. What is the content version that will include the new / updated signature?
- I heard the target Antivirus version that will include the fix of an Antivirus signature. When will the Antivirus package version XXXX be released?
Environment
- Threat Prevention License
Answer
The content release version is not fixed before its release. Palo Alto Networks runs some tests before releasing signatures. The target release week may vary depending on the test result.
Also, if an emergency content package is released, the target version can change.
So, please be advised to monitor the content release notes and look for the corresponding signature.
On the other hand, the Antivirus package version is decided before its release. (It may still vary in some situations.)
Based on the target release version and the current latest version, you will know roughly when the target will be released. For example, if the target release version is Antivirus package 1234 and if the current latest version is 1233, the fix will be released within 24 hours because Antivirus packages are released every 24 hours.
Reference:
PAN-OS Upgrade Guide - "Dynamic Content Updates"
If a false positive was happening only with a WildFire Real-Time signature (in other words, if the signature was already replaced in the past and not being released in an Antivirus package), the corresponding signature won't appear in the Antivirus release notes. In this case, the fix takes effect immediately right after the signature gets disabled.
Reference:
What is the meaning of "In Current Release: No" on Threat Vault?