Advanced DNS Security
Stops the 85% of malware that abuses DNS — tunneling, DGA, and C2.
Palo Alto Networks Advanced DNS Security protects the DNS layer, which Unit 42 found 85% of malware leverages. It stops advanced and evasive DNS-based threats — DNS tunneling, domain generation algorithms (DGA), command-and-control, and DNS zone hacks — that other tools miss, blocking malicious domains before they can be reached. Faltrox enables and operates it as a Cloud-Delivered Security Service on your NGFWs.
Overview
What Advanced DNS Security is
DNS is a favourite channel for attackers — Palo Alto Networks Unit 42 found that 85% of malware leverages DNS for command-and-control, data exfiltration, or reaching malicious infrastructure — yet many defences barely inspect it. Advanced DNS Security closes that gap, protecting the DNS layer against the advanced and evasive threats that hide there.
Delivered as a Cloud-Delivered Security Service on the NGFW, it blocks advanced threats like DNS tunneling, C2, DGA-generated domains, and DNS zone hacks and abuse, using machine learning to catch newly registered and likely-malicious domains before a connection is made. It protects productivity by stopping malicious domains without breaking legitimate DNS, and shares intelligence across the platform. Faltrox enables it, tunes the policy, and operates its detections as part of managed defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
DNS Layer
Protects the DNS layer that 85% of malware abuses for C2 and exfiltration.
DNS Tunneling
Detects and blocks DNS tunneling used to exfiltrate data and hide C2.
DGA Domains
Machine learning catches domain-generation-algorithm domains before they resolve.
Command & Control
Blocks DNS-based command-and-control callbacks at the resolution layer.
DNS Zone Abuse
Stops DNS zone hacks and abuse that compromise trusted infrastructure.
Malicious Domains
Blocks newly registered and likely-malicious domains before a connection is made.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Resolve
DNS requests pass through the NGFW where Advanced DNS Security inspects them in line with resolution.
- 02
Analyse
Machine learning analyses domains for DGA patterns, tunneling, and likely-malicious characteristics in real time.
- 03
Block
Malicious domains, tunneling, C2, and zone abuse are blocked before a connection is established.
- 04
Preserve Productivity
Legitimate DNS is preserved while malicious activity is stopped, avoiding broad breakage.
- 05
Operate
Faltrox tunes the policy and operates the detections as part of managed defence.
Capabilities
Key capabilities
DNS-Layer Protection
Protects against the DNS-based threats that 85% of malware leverages, per Unit 42.
DNS Tunneling Detection
Detects and blocks DNS tunneling used for data exfiltration and covert C2.
DGA Detection
Machine learning catches domain-generation-algorithm domains before they resolve.
C2 Prevention
Blocks DNS-based command-and-control callbacks at the resolution layer.
DNS Zone Protection
Stops DNS zone hacks and abuse that compromise trusted infrastructure.
Malicious Domain Blocking
Blocks newly registered and likely-malicious domains before connection.
Productivity Preservation
Stops malicious DNS without breaking legitimate resolution and productivity.
Cloud-Delivered
A subscription on the NGFW with intelligence shared across the platform.
Works with
Part of the platform
Palo Alto Networks products this pairs with, and the Faltrox services that operate it.
Palo Alto Networks products
Faltrox services
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Palo Alto Networks Advanced DNS Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Why focus specifically on DNS?
Because Palo Alto Networks Unit 42 found that 85% of malware leverages DNS — for command-and-control, data exfiltration, and reaching malicious infrastructure — yet many defences barely inspect it. Protecting the DNS layer closes a channel most malware relies on.
02What is DNS tunneling and how does it catch it?
DNS tunneling hides data or C2 traffic inside DNS queries to evade detection. Advanced DNS Security uses analysis and machine learning to identify the patterns of tunneling and block it — a technique that ordinary DNS filtering does not detect.
03How does it catch domains that do not exist yet?
Attackers use domain-generation algorithms (DGA) to create huge numbers of throwaway domains. Machine learning recognises the characteristics of DGA and newly registered malicious domains and blocks them before they resolve, rather than waiting for them to appear on a blocklist.
04Will it break legitimate DNS?
No — it is designed to stop malicious domains and DNS abuse while preserving legitimate resolution and productivity, so protection does not come at the cost of broad breakage. Faltrox tunes the policy to your environment.
05How does Faltrox operate it?
We enable it on your NGFWs, tune the DNS security policy, and operate its detections — folding DNS-layer protection into the managed network defence and SOC services we run.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us