MALWARE PATROL FOR PALO ALTO
Feed Your Firewall: Advanced Threat Intel for PAN NGFW
Unleash the full potential of your Palo Alto Next-Generation Firewall (NGFW) by integrating it with Malware Patrol’s threat intelligence. Designed for compatibility with Palo Alto’s industry-leading platform, our feeds deliver real-time, actionable data that extends your firewall’s ability to detect, block, and neutralize a wide spectrum of cyber threats.
We offer the following threat feeds formatted specifically for PAN NGFW:
- DNS-over-HTTPS (DoH) Servers: This feed helps you monitor and control encrypted DNS traffic in your environment. DoH can obscure malicious communications by tunneling DNS queries through HTTPS, a tactic used by multiple malware families for stealthy C2 connections. Blocking known DoH servers restores visibility and control over this evasive threat vector.
- Malicious Domains: Block connections to domains linked to phishing, ransomware, malware, cryptojacking, and command-and-control infrastructure. Cutting off C2 communication disrupts the attack chain which prevents data exfiltration, payload deployment, and ransomware encryption before damage is done.
- Malicious IP Addresses: This feed includes IPs currently serving malware, hosting C2 servers, or used in active threat campaigns. Blocking these addresses reduces exposure to evolving or unknown threats sharing the same infrastructure.
- Malware & Ransomware URLs: Achieve precision blocking at the URL level. This feed enables you to stop access to malicious files or payloads without affecting entire domains. This is especially valuable when threats are hosted on trusted platforms like Dropbox or Google Drive. Avoid collateral damage while keeping users protected.
PAN NGFW Configuration Guides
Our written guide is available here.
Pre-integration: Create website certificate profiles required for EDLs
Integrate Malware Patrol’s Malicious IPs Feed
Integrate Malware Patrol’s Malicious Domains Feed
Integrate Malware Patrol’s Malware and Ransomware URLs feed
About Palo Alto NGFW
Palo Alto Networks NGFW features:
“Quickly and accurately profile any IoT device to reveal its type, vendor, model, firmware and more while using cloud scale to compare device usage, validate profiles and fine-tune models so devices don’t go unmanaged.
With zero-delay signatures, every internet-connected NGFW in a network is updated within single-digit seconds of an analysis, ensuring the first user to see a threat is the only user to see that threat.
Use AIOps to deliver high ROI — improve your security posture without adding staff or buying new equipment, and avoid costly outages by predicting firewall health.”