Palo Alto NetworksCloud-Delivered Security Services

    Advanced DNS Security

    Stops the 85% of malware that abuses DNS — tunneling, DGA, and C2.

    Palo Alto Networks Advanced DNS Security protects the DNS layer, which Unit 42 found 85% of malware leverages. It stops advanced and evasive DNS-based threats — DNS tunneling, domain generation algorithms (DGA), command-and-control, and DNS zone hacks — that other tools miss, blocking malicious domains before they can be reached. Faltrox enables and operates it as a Cloud-Delivered Security Service on your NGFWs.

    Overview

    What Advanced DNS Security is

    DNS is a favourite channel for attackers — Palo Alto Networks Unit 42 found that 85% of malware leverages DNS for command-and-control, data exfiltration, or reaching malicious infrastructure — yet many defences barely inspect it. Advanced DNS Security closes that gap, protecting the DNS layer against the advanced and evasive threats that hide there.

    Delivered as a Cloud-Delivered Security Service on the NGFW, it blocks advanced threats like DNS tunneling, C2, DGA-generated domains, and DNS zone hacks and abuse, using machine learning to catch newly registered and likely-malicious domains before a connection is made. It protects productivity by stopping malicious domains without breaking legitimate DNS, and shares intelligence across the platform. Faltrox enables it, tunes the policy, and operates its detections as part of managed defence.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    DNS Layer

    Protects the DNS layer that 85% of malware abuses for C2 and exfiltration.

    02

    DNS Tunneling

    Detects and blocks DNS tunneling used to exfiltrate data and hide C2.

    03

    DGA Domains

    Machine learning catches domain-generation-algorithm domains before they resolve.

    04

    Command & Control

    Blocks DNS-based command-and-control callbacks at the resolution layer.

    05

    DNS Zone Abuse

    Stops DNS zone hacks and abuse that compromise trusted infrastructure.

    06

    Malicious Domains

    Blocks newly registered and likely-malicious domains before a connection is made.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Resolve

      DNS requests pass through the NGFW where Advanced DNS Security inspects them in line with resolution.

    2. 02

      Analyse

      Machine learning analyses domains for DGA patterns, tunneling, and likely-malicious characteristics in real time.

    3. 03

      Block

      Malicious domains, tunneling, C2, and zone abuse are blocked before a connection is established.

    4. 04

      Preserve Productivity

      Legitimate DNS is preserved while malicious activity is stopped, avoiding broad breakage.

    5. 05

      Operate

      Faltrox tunes the policy and operates the detections as part of managed defence.

    Capabilities

    Key capabilities

    DNS-Layer Protection

    Protects against the DNS-based threats that 85% of malware leverages, per Unit 42.

    DNS Tunneling Detection

    Detects and blocks DNS tunneling used for data exfiltration and covert C2.

    DGA Detection

    Machine learning catches domain-generation-algorithm domains before they resolve.

    C2 Prevention

    Blocks DNS-based command-and-control callbacks at the resolution layer.

    DNS Zone Protection

    Stops DNS zone hacks and abuse that compromise trusted infrastructure.

    Malicious Domain Blocking

    Blocks newly registered and likely-malicious domains before connection.

    Productivity Preservation

    Stops malicious DNS without breaking legitimate resolution and productivity.

    Cloud-Delivered

    A subscription on the NGFW with intelligence shared across the platform.

    Works with

    Part of the platform

    Palo Alto Networks products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Palo Alto Networks Advanced DNS Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Why focus specifically on DNS?

    Because Palo Alto Networks Unit 42 found that 85% of malware leverages DNS — for command-and-control, data exfiltration, and reaching malicious infrastructure — yet many defences barely inspect it. Protecting the DNS layer closes a channel most malware relies on.

    02What is DNS tunneling and how does it catch it?

    DNS tunneling hides data or C2 traffic inside DNS queries to evade detection. Advanced DNS Security uses analysis and machine learning to identify the patterns of tunneling and block it — a technique that ordinary DNS filtering does not detect.

    03How does it catch domains that do not exist yet?

    Attackers use domain-generation algorithms (DGA) to create huge numbers of throwaway domains. Machine learning recognises the characteristics of DGA and newly registered malicious domains and blocks them before they resolve, rather than waiting for them to appear on a blocklist.

    04Will it break legitimate DNS?

    No — it is designed to stop malicious domains and DNS abuse while preserving legitimate resolution and productivity, so protection does not come at the cost of broad breakage. Faltrox tunes the policy to your environment.

    05How does Faltrox operate it?

    We enable it on your NGFWs, tune the DNS security policy, and operate its detections — folding DNS-layer protection into the managed network defence and SOC services we run.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us