Vendor en Product Informatie

WildFire™ cloud-based threat analysis service

Automatically Prevent Highly Evasive Zero-Day Exploits and Malware  

WildFire™ cloud-based threat analysis service is the industry’s most advanced analysis and prevention engine for highly evasive zero-day exploits and malware. The cloud-based service employs a unique multi-technique approach combining dynamic and static analysis, innovative machine learning techniques, and a groundbreaking bare metal analysis environment to detect and prevent even the most evasive threats.

Find the Unknown With a Unique Multi-Technique Approach

WildFire goes beyond legacy approaches used to detect unknown threats, bringing together the benefits of four independent techniques for high-fidelity and evasion-resistant discovery, including:

  • Dynamic analysis: Observes files as they detonate in a custom-build evasion resistant virtual environment, enabling detection of zero-day malware and exploits using hundreds of behavioral characteristics.
  • Static analysis: Highly effective detection of malware and exploits that attempt to evade dynamic analysis, as well as instantly identifying variants of existing malware.
  • Machine learning: Extracts thousands of unique features from each file, training a predictive machine learning classifier to identify new malware and exploits not possible with static or dynamic analysis alone.
  • Bare metal analysis: Evasive threats are automatically sent to a real hardware environment for detonation, entirely removing an adversary’s ability to deploy anti-VM analysis techniques.

Together, these techniques allow WildFire to discover and automatically prevent unknown exploits and malware with high efficacy and near-zero false positives.

The Power of the Threat Intelligence Cloud

As part of the Palo Alto Networks Threat Intelligence Cloud, WildFire is the world’s largest distributed sensor system focused on identifying and preventing unknown threats, with more than 15,500 enterprise, government, and service providers contributing to the collective immunity of all other users. When a novel malware or exploit is seen, WildFire automatically creates and shares a new prevention control in about 5 minutes, without human intervention.

WildFire also forms the central prevention orchestration point for the Palo Alto Networks Next-Generation Security Platform, allowing the enforcement of new controls across:

  • Threat Prevention to block malware, exploits, as well as command-and-control (anti-C2 and DNS-based callback) activity.
  • URL Filtering with PAN-DB for the prevention of newly discovered malicious URLs.
  • AutoFocus™ contextual threat intelligence service, enabling the extraction, correlation, and analytics of threat intelligence with high relevance and context.
  • Traps™ advanced endpoint protection and Aperture™ SaaS security service for real-time verdict determination and threat prevention.
  • Integration with our technology partners for verdict determination on third-party services with the WildFire API.

Threat Intelligence, Analytics, and Correlation

In combination with WildFire, organizations can use AutoFocus to hone in on the most targeted threats with high relevance and context. AutoFocus provides the ability to hunt across all data extracted from WildFire, as well as correlate indicators of compromise (IoCs) and samples with human intelligence from the Unit 42 threat research team. Together, WildFire and AutoFocus provide a complete picture into unknown threats targeting your organization and industry, and speed your ability to quickly take action on intelligence, without adding specialized security staff.

Deployment Options That Meet Privacy Needs

WildFire is available in multiple deployment modes, which can meet even the strictest local privacy or regulatory requirements, including:

  • Global cloud for high fidelity detection and immense scale, without additional hardware.
  • Private cloud with an on-premise WildFire appliance to meet privacy and regulatory requirements.
  • Hybrid cloud combining the benefits of both global and private cloud options.
  • European Union (EU) cloud for organizations in the EU with regional data privacy needs.


See how WildFire works together with the Palo Alto Networks Next-Generation Security Platform to automatically identify and prevent unknown attacks in 300 seconds, across the network, endpoint and cloud.


Enrich WildFire with groundbreaking threat intelligence and analytics capabilities with AutoFocus. See how they provide high degrees of relevance, correlation and context for the most advanced threats.   



Get the full details on how WildFire brings together dynamic and static analysis with machine learning to identify and automatically prevent unknown threats.   




Security Lifecycle Review

Get the details behind unknown threats impacting your organization with the Security Lifecycle Review (SLR). You’ll be able to understand your organization’s risk posture, including malware, vulnerability exploits and command-and-control activity observed on your network.




Peter Woest

Business Development Manager

+31 6 31756399