Enable defenders: Configure Palo Alto Networks Firewalls to block or alert on C2 URL traffic

Below is a resilience recommendation our customers have implemented recently to start you off on the path towards security improvement.


Risk:
Palo Alto Networks firewalls that use the default configuration for the 'command-and-control' URL category may not alert, block or log some malicious activity for your defenders.

Details:
Palo Alto Networks released a new URL category called ‘command-and-control’ on October 25th, 2017 to distinguish beaconing activity from malware downloads. At the time of release, only clients running PAN-OS 8.0.2+ with content 783+ had this category automatically set to “block”. PAN firewalls that did not meet these criteria were set to allow the traffic by default. This could result in traffic related to a compromise passing through without any alerting, blocking, or logging of the activity.

Impact:
MEDIUM

MItigate:
Ensure the Command-and-Control URL category is not set to “allow”, and instead is set to BLOCK or ALERT.

To learn more about this URL category, visit:  https://live.paloaltonetworks.com/t5/Management-Articles/Command-and-Control-C2-FAQ/ta-p/178617 

See another example here.


What is resilience?

Resilience is our way of making you better even when there aren’t any security incidents.

At its core, resilience is comprised of recommendations that describe:

  • A specific security risk

  • The potential impact, and

  • The steps to mitigate it

Resilience recommendations do one of two things – disrupt attackers or enable defenders. Recommendations that disrupt attackers prevent threats from successfully performing their intended goal, while recommendations that enable defenders allow your team (including us) to respond more effectively when they do.

Resilience recommendations cover a broad spectrum of security content from Windows settings that reduce the exposure of plain text credentials in-memory to specific configurations for getting the most out of your firewall or endpoint detection and response (EDR) solution.

Learn how to disrupt attackers and enable defenders using resilience on the exe blog.

 

Gartner, Market Guide for Managed Detection and Response Services, Toby Bussa, Kelly M. Kavanagh, Sid Deshpande, Craig Lawson, Pete Shoard, 15 July 2019

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and is used herein with permission. All rights reserved.

Gartner Disclaimer
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Gartner, Ask These Critical Questions and Consider These Risks When Selecting an MDR Provider, Toby Bussa, Kelly Kavanagh, Craig Lawson, Pete Shoard, 31 October 2019
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and is used herein with permission. All rights reserved.
Gartner Disclaimer
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Lorem ipsum dolor sit amet

Ut Enim Minima

Sed ut perspiciatis unde omnis iste natus error sit voluptatem!

Quis Autem Vel

Nemo enim ipsam voluptatem quia voluptas sit odit aut fugit!

Quo Voluptas

Ut enim ad minima veniam, quis nostrum exercitationem ullam!

Ut Enim Minima

Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem.

Quis Autem Vel

Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit

Quo Voluptas

Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem.

Consectetur adipiscing elit...

Joanna C.

"Et harum quidem rerum facilis est et expedita distinctio!"

Stanley T.

"Nam libero tempore, cum soluta nobis est eligendi."

Danielle W.

"Temporibus autem quibusdam et aut officiis debitis!"