Palo Alto NetworksCloud-Delivered Security Services

    Advanced Threat Prevention

    The IPS reimagined — inline, ML-based prevention of zero-day exploits and C2.

    Palo Alto Networks Advanced Threat Prevention is the intrusion prevention system reimagined — the first IPS to stop zero-day attacks inline using cloud-based deep learning. It stops 60% more zero-day injection attacks and 48% more high-evasion command-and-control than traditional IPS, blocking never-before-seen threats in real time rather than waiting on signatures. Faltrox enables and tunes it as a Cloud-Delivered Security Service on your NGFWs.

    Overview

    What Advanced Threat Prevention is

    Traditional intrusion prevention relies on signatures and catches only what has been seen before, leaving zero-day exploits and evasive command-and-control to slip through. Advanced Threat Prevention (ATP) rethinks the IPS: it adds inline cloud-based deep-learning models that analyse traffic in real time and block never-before-seen attacks as they happen.

    Delivered as a Cloud-Delivered Security Service on the Palo Alto Networks NGFW, it is the first IPS to stop zero-day attacks inline — stopping 60% more zero-day injection attacks and 48% more high-evasion C2 than the closest competitor. It uses inline machine learning to detect command-and-control, exploits, and evasive malware, and shares protections automatically across the platform. Faltrox enables ATP on your firewalls, tunes the policy, and operates the detections it produces as part of managed network defence.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Zero-Day Exploits

    Inline deep learning stops never-before-seen exploits, including injection attacks, in real time.

    02

    Command & Control

    Blocks evasive C2 callbacks, stopping 48% more high-evasion C2 than the closest competitor.

    03

    Evasive Malware

    Detects malware and post-exploitation activity that signature IPS misses.

    04

    Known Attacks

    Full signature-based intrusion prevention for known exploits and vulnerabilities.

    05

    Network Traffic

    Inspects traffic inline on the NGFW without a separate appliance.

    06

    Automated Protections

    New protections propagate automatically across the platform as threats are found.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Inspect

      Traffic passes through the NGFW where ATP inspects it inline for exploits, C2, and evasive malware.

    2. 02

      Analyse

      Cloud-based deep-learning models analyse suspicious traffic in real time to catch never-before-seen attacks.

    3. 03

      Block Inline

      Zero-day exploits and evasive C2 are blocked as they happen — not after a signature is written.

    4. 04

      Share

      New protections are automatically shared across the Cloud-Delivered Security Services and the platform.

    5. 05

      Operate

      Faltrox tunes the policy and operates the detections as part of managed network defence.

    Capabilities

    Key capabilities

    Inline Zero-Day Prevention

    The first IPS to stop zero-day attacks inline using cloud-based deep learning, in real time.

    Inline ML C2 Detection

    Inline machine learning stops 48% more high-evasion command-and-control than the closest competitor.

    Injection Attack Prevention

    Stops 60% more zero-day injection attacks than traditional IPS.

    Signature IPS

    Full signature-based intrusion prevention for known exploits and vulnerabilities.

    Evasion Coverage

    Detects high-evasion techniques and post-exploitation activity that signatures miss.

    Cloud-Delivered

    Delivered as a subscription on the NGFW with no additional appliance to deploy.

    Automated Protection Sharing

    New protections propagate automatically across the platform as threats are discovered.

    Unit 42 Intelligence

    Backed by Unit 42 threat research feeding continuously updated protections.

    Works with

    Part of the platform

    Palo Alto Networks products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Palo Alto Networks Advanced Threat Prevention for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01How is this different from a traditional IPS?

    A traditional IPS relies on signatures and catches only known attacks. Advanced Threat Prevention adds inline cloud-based deep learning that analyses traffic in real time and blocks never-before-seen zero-day exploits and evasive C2 as they happen — it is the first IPS to stop zero-day attacks inline.

    02Does inline analysis slow the firewall down?

    The deep-learning analysis runs in the cloud with an architecture designed for inline real-time verdicts, so it prevents zero-day threats without the latency of taking traffic offline for analysis. Faltrox tunes it for your throughput.

    03Is it a separate appliance?

    No — it is a Cloud-Delivered Security Service subscription that runs on your existing Palo Alto Networks NGFWs, so there is no additional hardware to deploy. New protections are shared automatically across the platform.

    04What kinds of attacks does it stop that signatures miss?

    Zero-day injection attacks (60% more than traditional IPS), high-evasion command-and-control (48% more than the closest competitor), and evasive malware and post-exploitation activity — the never-before-seen and evasive threats that signature-only IPS structurally cannot catch.

    05How does Faltrox operate it?

    We enable ATP on your NGFWs, tune the threat policy, and operate the resulting detections as part of the managed network defence and SOC services we run — so inline zero-day prevention is delivered as a service, not just a licence.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us