Palo alto Community News 2024年10月01日
July 2023 Rewind: LIVEcommunity Highlights
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

LIVEcommunity七月回顾涵盖了安全最佳实践、Azure vWAN保护、成员访谈和PANCast最新剧集等内容。文章重点介绍了利用XQL进行威胁狩猎和事件分析的最佳实践,以及在Azure中保护vWAN的必要性。此外,文章还分享了成员访谈,展示了社区成员如何利用LIVEcommunity获取技术支持和最新信息。最后,文章还介绍了PANCast最新剧集,探讨了Cortex XDR代理日志分析和Azure容器注册表配置等主题。

📈 **XQL最佳实践:** 文章介绍了Cortex Query Language (XQL) 的最佳实践,包括如何优化查询性能,以及如何利用其强大的功能来简化数据分析工作流程。文章还提供了利用XQL进行威胁狩猎和事件分析的具体建议,帮助用户更好地理解和应用XQL。

💻 **Azure vWAN安全:** 文章强调了在Azure中保护vWAN的重要性,并介绍了vWAN的主要特征和优势。文章还解释了为什么保护vWAN对于扩展Azure基础设施至关重要,并提供了相关安全建议。

📡 **成员访谈:** 文章分享了社区成员Andrew Kahn的访谈,展示了他在使用LIVEcommunity获取技术支持和最新信息方面的经验。Andrew分享了他在使用LIVEcommunity过程中遇到的挑战和解决方案,以及他如何利用LIVEcommunity来提升自己的技术技能。

📷 **PANCast最新剧集:** 文章介绍了PANCast最新剧集,包括Cortex XDR代理日志分析和Azure容器注册表配置等主题。PANCast是Palo Alto Networks推出的播客节目,旨在为用户提供安全专家提供的可操作见解,帮助用户提升安全意识和技能。

📥 **威胁研究:** 文章介绍了Unit 42研究人员发现的近期攻击活动,包括利用恶意OneNote附件进行攻击,以及Cloaked Ursa利用针对外交官的诱饵进行攻击。文章还分享了针对这些攻击活动的防御建议和安全最佳实践。

📗 **社区讨论:** 文章介绍了LIVEcommunity中一些热门的讨论主题,包括有关安全最佳实践、Azure vWAN保护和威胁研究的讨论。文章还展示了社区成员如何通过这些讨论来获取技术支持和分享经验。

 Welcome to our July 2023 Rewind, where we review some of LIVEcommunity’s biggest headlines from the past month! In July, we shared information on securing vWAN using Cloud NGFW for Azure, a LIVEcommunity member testimonial featuring Andrew Kahn, and the latest episodes of PANCast, and more! Read on to see community's July 2023 highlights.  XDR Best Practices: 5 Tips For Better XQL QueriesThe Cortex Query Language (XQL) is an advanced query language, built on top of BigQuery (GoogleSQL), that enables you to query data ingested into Cortex XDR and XSIAM for rigorous endpoint and network event analysis. By leveraging the full potential of XQL, you can enhance threat hunting, investigation, and other critical security operations. In this blog post, we will provide some key tips and best practices for utilizing XQL more effectively, optimizing query performance, and leveraging its powerful features to streamline your data analysis workflows. This blog contains useful information and prepwork for backup procedures to move XSOAR from an old machine to a new machine.  If there’s a high chance that you already have dozens, if not hundreds, of virtual networks in Azure, then this blog is for you!  Whether your migration was a “lift-and-shift” or “ landing zone” type, you have likely come across the virtual wide area network (vWAN) and the benefits it offers while expanding your Azure footprint. Read more to quickly go through the main characteristics of the vWAN to explain why securing it is a big deal.  This document describes the use-cases, architecture design and traffic flows for Palo Alto Networks VM-Series deployed in Active-Passive mode in Google Cloud. The Active-Passive architecture provides several advantages over the Active-Active architecture like stateful failover, eliminates several source NAT requirements, and can be used for static IPSec termination. This document is intended for network administrators, solution architects, and security professionals who are familiar with Compute Engine, Load Balancing and Virtual Private Cloud (VPC) networking. In this member testimonial — a video series that invites community members from around the world to share their experience on LIVEcommunity — Andrew explains that he uses the LIVEcommunity daily to get answers to technical questions and stay up-to-date with the latest updates and developments on Palo Alto Networks technology. He finds LIVEcommunity to be a valuable resource for discovering best practices and learning about new features of Palo Alto Networks firewalls. We hope you agree! New PANCast Episodes Are Out! PANCast is a Palo Alto Networks podcast that provides actionable insights from cybersecurity experts to customers, helping them ensure each day is more secure than the one before it. Visit our PANCast homepage to learn more and watch our previous podcasts in this series. PANCast Episode 21: Cortex XDR Agent Logs and Operational Status Analysis   PANCast Episode 22: Azure Container Registry and Configuring Scanning Using Service Principal  Unit 42 researchers discovered an active campaign that targeted several web hosting and IT providers in the United States and European Union from late 2020 to late 2022. Unit 42 tracks the activity associated with this campaign as CL-CRI-0021 and believes it stems from the same threat actor responsible for the previous campaign known as Manic Menagerie. The threat actor deployed coin miners on hijacked machines to abuse the compromised servers’ resources. They have further deepened their foothold in victims’ environments by mass deployment of web shells, which granted them sustained access, as well as access to internal resources of the compromised websites. Read this blog to learn more information on threat actors and their evolution. The Cortex Threat Research team has been tracking recent campaigns that were using malicious OneNote email attachments as the initial attack vector. Malicious OneNote files have been made popular by various threat actors earlier this year, as a response to Microsoft blocking internet macros by default. In correlation with Microsoft’s notice, starting in early 2023, OneNote infected attachments have been seen spreading malware such as Emotet, Qakbot, and AsyncRAT to name a few. Read this Cyber Elite-written blog for more information on helpful SASE security tips. Recently, Unit 42 researchers observed instances of Cloaked Ursa using lures focusing on the diplomats themselves more than the countries they represent. We have identified Cloaked Ursa targeting diplomatic missions within Ukraine by leveraging something that all recently placed diplomats need – a vehicle. July ‘23 Discussion Highlight: Posts With Accepted Solutions Nominated Discussions help LIVEcommunity Solutions Engineers highlight a discussion that has an Accepted Solution, and turn it into an article with additional helpful information, documentation, and clarity! Here are the Nominated Discussions we published this past month: 

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

LIVEcommunity 安全最佳实践 Azure vWAN XQL 威胁狩猎 PANCast Cortex XDR Azure容器注册表 威胁研究 OneNote Cloaked Ursa
相关文章