Advanced URL Filtering
The industry’s first real-time, ML-powered web protection engine.
Palo Alto Networks Advanced URL Filtering delivers best-in-class web protection with the industry’s first real-time web protection engine, powered by machine learning. It analyses and blocks malicious and phishing URLs the moment they are accessed — catching the web-based attacks like phishing, ransomware, and fileless attacks that traditional URL databases miss because they act too late. Faltrox enables and tunes it on your NGFWs.
Overview
What Advanced URL Filtering is
Web-based attacks like phishing and fileless attacks are common and fast — and traditional URL filtering relies on databases that are always a step behind, missing newly created malicious sites. Advanced URL Filtering combines database capabilities with the industry’s first real-time web protection engine, powered by machine learning, to analyse and block web-based threats instantly.
Delivered as a Cloud-Delivered Security Service on the NGFW, it inspects URLs and web content in real time to stop phishing, malware, ransomware, and command-and-control at the point of access — preventing significantly more threats than traditional filtering by catching sites the moment they turn malicious rather than after they are catalogued. It integrates with the rest of the platform’s services. Faltrox enables it, tunes the categories and policy, and operates its detections as part of managed web defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Phishing URLs
Real-time analysis blocks credential-phishing sites the moment they are accessed.
Malware & Ransomware
Stops malware- and ransomware-hosting sites, including newly created ones.
Fileless Attacks
Catches the fast, fileless web-based attacks that database-only filtering misses.
Command & Control
Blocks web-based command-and-control communication at the URL layer.
Acceptable Use
Category-based filtering enforces acceptable-use and reduces attack surface.
Newly Registered Sites
Real-time engine catches malicious sites before a database would list them.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Access
A user requests a URL, which passes through the NGFW’s Advanced URL Filtering service.
- 02
Analyse
The real-time, ML-powered web protection engine analyses the URL and content instantly, not just against a database.
- 03
Block
Malicious, phishing, ransomware, and C2 URLs are blocked at the point of access — including newly created ones.
- 04
Categorise
Category-based policy enforces acceptable-use and reduces the web attack surface.
- 05
Operate
Faltrox tunes the categories and policy and operates the detections as part of managed web defence.
Capabilities
Key capabilities
Real-Time Web Engine
The industry’s first real-time web protection engine analyses and blocks threats instantly.
ML-Powered Detection
Machine learning catches newly created malicious sites that database-only filtering misses.
Phishing Prevention
Blocks credential-phishing sites in real time at the moment of access.
Malware & Ransomware Blocking
Stops sites hosting malware, ransomware, and fileless attacks.
C2 Prevention
Blocks web-based command-and-control communication at the URL layer.
Category Filtering
Category- and reputation-based filtering enforces acceptable-use policy.
Cloud-Delivered
A subscription on the NGFW with no additional appliance to deploy.
Platform Integration
Shares intelligence with the rest of the Cloud-Delivered Security Services.
Works with
Part of the platform
Palo Alto Networks products this pairs with, and the Faltrox services that operate it.
Palo Alto Networks products
Faltrox services
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Palo Alto Networks Advanced URL Filtering for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Why "real-time" — what was wrong with URL databases?
URL databases are always a step behind: a newly created phishing or malware site is not catalogued until after it has been seen and analysed, so early victims are unprotected. Advanced URL Filtering adds a real-time ML engine that analyses the site the moment it is accessed, catching threats a database would miss.
02What threats does it stop?
Web-based attacks — phishing, malware, ransomware, fileless attacks, and command-and-control — at the point of access. It prevents significantly more threats than traditional filtering by catching sites the moment they turn malicious.
03Is it a separate product or part of the firewall?
It is a Cloud-Delivered Security Service subscription that runs on your Palo Alto Networks NGFWs (and Prisma Access), so there is no separate appliance — it enhances the firewalls you already run.
04Does it also handle acceptable-use policy?
Yes — alongside real-time threat blocking it provides category- and reputation-based filtering to enforce acceptable-use policy and reduce the web attack surface. Faltrox tunes the categories to your requirements.
05How does Faltrox operate it?
We enable it on your NGFWs, tune the categories and policy, and operate its detections as part of the managed web and network defence we run — delivering real-time web protection as a service.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us