TrustRadius: an HG Insights company

Palo Alto Networks WildFire

Score9.8 out of 10

36 Reviews and Ratings

What is Palo Alto Networks WildFire?

Palo Alto Network’s WildFire is a malware prevention service. It specializes in addressing zero-day threats through dynamic and static analysis, machine learning, and advanced sandbox testing environments.

Read more details.

Videos

Who Buys & Uses Palo Alto Networks WildFire

Palo Alto Networks WildFire is a strong layer in our security onion

Use Cases and Deployment Scope

Palo Alto Networks WildFire plays a critical role in strengthening our cybersecurity posture. We use it to detect and prevent unknown threats across our network, endpoints, and cloud environments. Palo Alto Networks WildFire analyzes suspicious files and URLs in real time. Once a threat is identified, Palo Alto Networks WildFire automatically shares updated protections across our infrastructure, reducing exposure time and improving response speed. Our SOC also relies on Palo Alto Networks WildFire’s detailed threat intelligence to investigate incidents. Since implementing Palo Alto Networks WildFire, we’ve significantly reduced false positives and improved our ability to respond to emerging threats. It has become a foundational part of our layered defense strategy, helping us stay ahead of rapidly evolving threats.

Pros

  • Malware prevention
  • Automated protection of multiple workloads cloud and on-prem
  • Improves incident response times and reduces false positives

Cons

  • The UI is needlessly complex in some cases.
  • HTTPS/SSL decryption is difficult to handle
  • Integration with our MDE isn't very helpful

Return on Investment

  • We seem to have reduced the number of security incidents after implementing Palo Alto Networks WildFire.
  • Our SOC has more time for other tasks due to fewer incidents and false-positives

Usability

Alternatives Considered

Fortinet FortiGate and Fortinet Security Fabric

Other Software Used

FortiAnalyzer, Fortinet FortiGate, FortiClient, Fortinet FortiExtender

A short note about WildFire

Use Cases and Deployment Scope

So when we are talking about WildFire, first thing which comes in our mind is Zero Day Attack. Zero Day Attack means when a new type of attack happen and firewall don't have any signature of this. So in this case WildFire comes into picture. Basically firewall sends a copy of file to WildFire where it WildFire runs the file in various environment and analysis the file. If the file is harmful and malicious WildFire update the signature in all the firewall. So in this way it prevents future attack .

Pros

  • It prevents Zero Day Attack
  • It updates the signature base of all firewall when new attack is found.
  • It run the file in virtual environment so that local pc isn't affect .
  • It is use to analyse the file before any false decision.

Cons

  • The main pain is that we have to purchase the WildFire Licence separately. I think it should be by default available in Palo Alto Firewall.
  • Sometimes it takes much time to analyse the file.
  • It provides result after attack is happened.

Most Important Features

  • The main features is that it helps to detect Zero Day Attack.
  • It updates the signature base of Firewall.
  • It runs over cloud so the CPU of firewall is not utilised.

Return on Investment

  • As we all know the product of Palo Alto is little bit expensive but its performance is far better than any of its competitors. So as I previously mentioned, Palo Alto should not sell WildFire Licence seperately.
  • If the firewall is internet facing then only we should buy WildFire Licence.
  • WildFire Licence is not necessary for internal firewall. If you are planning to buy a firewall for internal network where your traffic is not going towards internet so no need to buy WildFire Licence.

Alternatives Considered

CheckPoint

"An Intuitive, Simple-To-Implement, And The Best Sandboxing Solution"

Pros

  • It can detect potentially dangerous files of various kinds and operating system executable files as well. Integration of AutoFocus with Palo Alto solutions is one click.
  • Ensuring that you're protected against the newest dangers, including zero-day attacks. This is called zero-day monitoring.
  • By using Palo Alto's threat protection capabilities, the tool helps to alleviate compliance issues by enabling on-site sandboxing of files.
  • Cost-wise, it's competitive with other comparable solutions on the market, and it integrated well with current Palo Alto systems. Scalability and management simplicity are also significant advantages.

Cons

  • WildFire, like other sandboxes, has to stay up with malware sandbox evasion techniques, which necessitates larger file size limits.
  • More file formats should be able to be submitted and scanned by WildFire, which needs improved initial administration and setup.
  • It's quite pricey, and there's no warning choice for performance on the cloud.

Most Important Features

  • Problems are resolved, and smooth functioning is achieved.
  • File scanning and well-trained staff are two benefits.
  • There is no requirement for technical help, and the combined power of multiple WildFire threat signatures is accessible.

Return on Investment

  • Our ability to report third-party combat infiltration testing is enhanced by other customers' threat signatures.
  • The additional high-end security equipment demonstrates strong attention to sensitive data we handle and address IT security vulnerabilities.
  • Enhanced network visibility and unknown file analysis assist detect malware that lacks a current signature.

Alternatives Considered

Cisco ASA, FireEye Network Security and Juniper SRX

Other Software Used

Cisco ASA, Juniper SRX, Palo Alto Networks Traps

Catch a good value for low cost with exceptional features

Pros

  • Integration with Palo Alto solutions (very easy and one-click).
  • Zero day detection.
  • AutoFocus integration.
  • Leveraging the Palo Alto threat prevention features.
  • API integration with different solutions (many of them already built-in configurations).
  • Unit 42 threat research team behind the WildFire.
  • Integration with 3rd-party feeds.
  • Upcoming solutions and acquisitions of Palo Alto are integrated and built-in capability of WF usage.

Cons

  • Local WF appliance is lacking in term of functionality like no bare metal analysis in local solution.
  • No new features coming to local WF appliances.
  • No built-in integration with GlobalProtect Agent.
  • Cloud WF does not have the option for specific regions to be used (compliance).
  • Cloud side does not have alarming option for [degraded] performance.
  • Lack of forensics (needs additional product or integration).

Return on Investment

  • Adding it to the already implied PAN infrastructure is cheap compared to other vendors.
  • Opening WF integration on the Datacenter segmentation is somehow costly.
  • From the audit perspective it's covering the gaps of IT security.

Alternatives Considered

FireEye Network Security, Trend Micro Deep Discovery Analyzer and Check Point ThreatCloud

Other Software Used

FireEye Network Security, Trend Micro Deep Discovery Analyzer, Check Point Firewall Software Blade

Palo Alto Networks WildFire is a nice extra layer of protection

Pros

  • Helps block zero-day exploits
  • You get the combined power of other users' Palo Alto Networks WildFire file scanning signatures as well
  • Seamless install and very little to manage

Cons

  • Need larger file size limits
  • They need to be able to submit and scan more file types
  • Rather expensive

Most Important Features

  • Seamless functionality
  • File scanning
  • Aggregate power of other customers' Palo Alto Networks WildFire threat signatures

Return on Investment

  • Added power of other customers threat signatures
  • No real management overhead
  • Potential zero-day vulnerability blocking (e.g., wannacry)

Other Software Used

Concur Travel and Expense, Cisco Identity Services Engine (ISE), Mimecast Threat Intelligence