Review WildFire analysis details

For each file, Cortex XSIAM receives a file verdict and the WildFire Analysis Report. This report contains detailed sample information and behavior analysis in different sandbox environments, leading to the WildFire verdict. You can use the report to assess whether the file poses a real threat on an endpoint. The details in the WildFire analysis report for each event vary depending on the file type and the behavior of the file.

Drill down into WildFire analysis details

WildFire analysis details are available for files that receive a WildFire verdict. The Analysis Reports section includes the WildFire analysis for each testing environment based on the observed behavior for the file.

  1. Open the WildFire report.

    If you are investigating a case in the case detail view you can see artifact details on the Key Assets & Artifacts tab. Under Artifacts, identify a file with a WildFire verdict and click Wildfire Analysis Report (WF-report-icon.png). If you are analyzing an issue, hover over the issue and Investigate. You can open (WF-report-icon.png) the WildFire report of any file included in the issue's Causality Chain.

    Note

    Cortex XSIAM displays the preview of WildFire reports that were generated within the last couple of years. To view a report that was generated more than two years ago, you can download the report.

  2. Analyze the WildFire report.

    On the left side of the report, you can see all the environments in which the Wildfire service tested the sample. If a file is low risk and WildFire can easily determine that it is safe, only static analysis is performed on the file. Select the testing environment to review the summary and additional details. To learn more about the behavior summary, see WildFire Analysis Reports—Close Up.

  3. (Optional) Download the WildFire report.

    If you want to download the WildFire report as it was generated by the WildFire service, click (WF-report-download-icon.png). The report is downloaded in PDF format.

Report an incorrect verdict to Palo Alto Networks

If you know the WildFire verdict is incorrect, for example, WildFire assigned a Malware verdict to a file you wrote and know to be Benign, you can report an incorrect verdict to Cortex XSIAM to request the verdict change.

  1. Open the WildFire report and verify the verdict that you are reporting.
  2. Click Report Verdict as Incorrect (WF-report-verdict-as-incorrect-icon.png).
  3. Under Suggested Verdict, suggest a new verdict.
  4. Under Comment, enter any details that can help us to better understand why you disagree with the verdict.
  5. Under Email, verify your email address.
  6. Click OK.

    The threat team will perform further analysis of the sample to determine whether it should be reclassified. If a malware sample is determined to be safe, the signature for the file is disabled in an upcoming antivirus signature update. If a benign file is determined to be malicious, a new signature is generated. After the investigation is complete, you will receive an email describing the action that was taken.