Advanced Threat Prevention
The IPS reimagined — inline, ML-based prevention of zero-day exploits and C2.
Palo Alto Networks Advanced Threat Prevention is the intrusion prevention system reimagined — the first IPS to stop zero-day attacks inline using cloud-based deep learning. It stops 60% more zero-day injection attacks and 48% more high-evasion command-and-control than traditional IPS, blocking never-before-seen threats in real time rather than waiting on signatures. Faltrox enables and tunes it as a Cloud-Delivered Security Service on your NGFWs.
Overview
What Advanced Threat Prevention is
Traditional intrusion prevention relies on signatures and catches only what has been seen before, leaving zero-day exploits and evasive command-and-control to slip through. Advanced Threat Prevention (ATP) rethinks the IPS: it adds inline cloud-based deep-learning models that analyse traffic in real time and block never-before-seen attacks as they happen.
Delivered as a Cloud-Delivered Security Service on the Palo Alto Networks NGFW, it is the first IPS to stop zero-day attacks inline — stopping 60% more zero-day injection attacks and 48% more high-evasion C2 than the closest competitor. It uses inline machine learning to detect command-and-control, exploits, and evasive malware, and shares protections automatically across the platform. Faltrox enables ATP on your firewalls, tunes the policy, and operates the detections it produces as part of managed network defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Zero-Day Exploits
Inline deep learning stops never-before-seen exploits, including injection attacks, in real time.
Command & Control
Blocks evasive C2 callbacks, stopping 48% more high-evasion C2 than the closest competitor.
Evasive Malware
Detects malware and post-exploitation activity that signature IPS misses.
Known Attacks
Full signature-based intrusion prevention for known exploits and vulnerabilities.
Network Traffic
Inspects traffic inline on the NGFW without a separate appliance.
Automated Protections
New protections propagate automatically across the platform as threats are found.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Inspect
Traffic passes through the NGFW where ATP inspects it inline for exploits, C2, and evasive malware.
- 02
Analyse
Cloud-based deep-learning models analyse suspicious traffic in real time to catch never-before-seen attacks.
- 03
Block Inline
Zero-day exploits and evasive C2 are blocked as they happen — not after a signature is written.
- 04
Share
New protections are automatically shared across the Cloud-Delivered Security Services and the platform.
- 05
Operate
Faltrox tunes the policy and operates the detections as part of managed network defence.
Capabilities
Key capabilities
Inline Zero-Day Prevention
The first IPS to stop zero-day attacks inline using cloud-based deep learning, in real time.
Inline ML C2 Detection
Inline machine learning stops 48% more high-evasion command-and-control than the closest competitor.
Injection Attack Prevention
Stops 60% more zero-day injection attacks than traditional IPS.
Signature IPS
Full signature-based intrusion prevention for known exploits and vulnerabilities.
Evasion Coverage
Detects high-evasion techniques and post-exploitation activity that signatures miss.
Cloud-Delivered
Delivered as a subscription on the NGFW with no additional appliance to deploy.
Automated Protection Sharing
New protections propagate automatically across the platform as threats are discovered.
Unit 42 Intelligence
Backed by Unit 42 threat research feeding continuously updated protections.
Works with
Part of the platform
Palo Alto Networks products this pairs with, and the Faltrox services that operate it.
Palo Alto Networks products
Faltrox services
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Palo Alto Networks Advanced Threat Prevention for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01How is this different from a traditional IPS?
A traditional IPS relies on signatures and catches only known attacks. Advanced Threat Prevention adds inline cloud-based deep learning that analyses traffic in real time and blocks never-before-seen zero-day exploits and evasive C2 as they happen — it is the first IPS to stop zero-day attacks inline.
02Does inline analysis slow the firewall down?
The deep-learning analysis runs in the cloud with an architecture designed for inline real-time verdicts, so it prevents zero-day threats without the latency of taking traffic offline for analysis. Faltrox tunes it for your throughput.
03Is it a separate appliance?
No — it is a Cloud-Delivered Security Service subscription that runs on your existing Palo Alto Networks NGFWs, so there is no additional hardware to deploy. New protections are shared automatically across the platform.
04What kinds of attacks does it stop that signatures miss?
Zero-day injection attacks (60% more than traditional IPS), high-evasion command-and-control (48% more than the closest competitor), and evasive malware and post-exploitation activity — the never-before-seen and evasive threats that signature-only IPS structurally cannot catch.
05How does Faltrox operate it?
We enable ATP on your NGFWs, tune the threat policy, and operate the resulting detections as part of the managed network defence and SOC services we run — so inline zero-day prevention is delivered as a service, not just a licence.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us