Blocking Attacker Infrastructure at the Network Layer: Advanced IP Defense for PAN-OS 12.2

Aug 20, 2026
6 minutes

Our Cloud-Delivered Security Services (CDSS) have set the industry standard for enterprise threat protection for a long time, consistently stopping complex, never-before-seen attacks across your network in real time. Yet, modern adversaries never stop hunting for unmonitored gaps at your perimeter. 

While working alongside our Unit 42 team, we uncovered a troubling trend. Attackers are systematically routing around standard domain and URL defenses. According to a recent Unit 42 Report, nearly 1 in 4 malware C2 sessions now circumvent DNS and URL inspections by going direct-to-IP, and inbound reconnaissance hides inside residential proxy networks with hundreds of thousands of IPs to jump between.

To address this shift head-on, our PAN-OS 12.2 Ceres release introduces Advanced IP Defense as a core network security capability. Built on the real-time, cloud-scale foundation of our CDSS suite, Advanced IP Defense extends Precision AI to your network layer. This critical boundary is where our internal analysis shows that 2 out of every 3 customer networks experience malicious activity that is completely preventable.

By disrupting adversary infrastructure before campaigns can unfold, Advanced IP Defense empowers your security team to block malicious connections long before they ever touch your environment.

Read on to learn what’s driving this adversary evolution, why traditional feeds can no longer keep up with modern attack speed and how you can modernize your threat prevention to stay ahead.

How Modern Adversaries Bypass Existing Defenses

Drawing from global telemetry across our CDSS footprint, Unit 42 researchers continuously monitor how adversary tactics evolve beneath traditional inspection controls. Let’s look into the mechanics behind the two evasion methods we touched on previously.

Blending Into Legitimate Traffic for Scans and Exploitation

On the inbound front, attackers are weaponizing automation and residential proxy networks to target your internet-facing assets. As highlighted by high-profile campaigns — including the massive 750,000-device consumer botnet reported by The Wall Street Journal — adversaries are routing automated brute-force probing, vulnerability scanning and exploitation attempts through legitimate home internet connections. 

By hiding behind everyday residential IPs, attackers easily mask their reconnaissance within benign consumer traffic, probing your perimeter entry points without triggering traditional blocklists. 

Circumventing Existing Inspections for Phone-Home Activity

While inbound tactics attempt to blend in, outbound tactics are engineered to sidestep standard defenses. In a Unit 42 study analyzing over 4 million Advanced WildFire software samples, researchers discovered that nearly 1 in 4 malware C2 traffic now connect direct to IP

In a separate investigation into OpenClaw AI supply chain risks, Unit 42 caught an OpenClaw agent tricked into establishing a direct-to-IP connection to pull down a malicious payload. It quietly slipped past outbound controls to exfiltrate sensitive data.

When adversaries rely on hard-coded IP addresses or hijacked consumer proxies, they circumvent traditional URL and domain inspections entirely.

Shortcomings of Legacy Feeds and Workflows

To counter these evasive network-layer tactics, security teams naturally look to block malicious infrastructure at the perimeter. This standard approach has relied on IP reputation feeds and static blocklists for years to meet this objective. These tools were designed for predictable, static IP addresses, however, not for today’s rapid infrastructure churn. The problem is that traditional feeds fail to protect modern networks due to the following critical shortcomings.

They’re just too slow. Historical industry benchmarks show that threat propagation took an average of 20 days postdetection. Because they are often enforced locally on a hardware device, the capacity of that specific device restricts them.

They drain your team’s resources by requiring heavy manual maintenance. These lists go stale almost immediately as attackers rotate their infrastructure. Security teams, therefore, must chase down false positives, further stretching their bandwidth.

Feeds lack context. Because the lists are static, they don’t give you the required intelligence to act with confidence. You are consequently left with a rigid, binary choice, especially when threats hide behind CDNs or shared hosts. You must block the IP and risk breaking business operations or set it to alert and overwhelm your SOC.

When security teams attempt to combat dynamic network-layer evasions using static feeds, the legacy delivery model cannot keep up with modern attacks. 

Extending Real-Time Prevention to the Network Layer

To overcome these legacy limitations, Advanced IP Defense extends threat protection to the network layer — replacing static feeds with a real-time, cloud-delivered protection that blocks attacker infrastructure outright.

At its core, the solution combines live global telemetry across more than 75,000 deployments and over 1,600 sources, zero trust IP correlation and dynamic risk profiling across more than 40 security attributes. When these capabilities work together, they transform how your team manages perimeter risk across three critical scenarios.

Minimizing exposure for internet-facing assets. 

The engine prescreens high-risk source networks — such as anonymizers, open proxies and weaponized consumer devices — before traffic touches entry points like VPN portals, web applications or DMZ servers. This approach dramatically shrinks your external attack surface and cuts down SOC alert noise.

Stopping evasive threats without business disruption.

By validating whether an outbound IP request correlates to legitimate DNS history, zero trust IP correlation catches stealthy direct-to-IP C2 sessions — including those hosted on shared cloud platforms and CDNs — without risking false positives on trusted business traffic.

Modernizing threat intel and eliminating feed overhead. 

Replacing manual blocklists with an automated cloud enforcement layer eliminates firewall table limits, erases 20-day intelligence lags and frees your team from the constant operational burden of managing stale feeds.

Advanced IP Defense

Closing the Blind Spot in Your Security Strategy

Moving past legacy defenses means stopping evasive infrastructure tactics that outpace static feeds and bypass standard perimeter controls entirely.

Outbound, when malware connects direct-to-IP, no DNS query occurs. It leaves domain and URL controls as well as reputation-based feeds blind. This gap is highlighted by the fact that, according to Unit 42 research, 52% of direct-to-IP addresses that Palo Alto Networks have identified were absent from major third-party threat feeds. Inbound, attackers use automation and rapidly rotating residential proxies to outpace static blocklists, disguising scanning and brute-force probing inside everyday consumer traffic long before traditional feeds can register the threat.

Bringing this back to where we started, the scale of this exposure comes down to two connected realities. Every day, we identify over 50,000 new malicious hosts across the internet — a massive churn of threat infrastructure that legacy feeds cannot track. Because static controls fail to keep up with that volume and speed, as we mentioned at the beginning of the blog, 2 out of 3 customer networks currently experience malicious activity that is preventable at the network layer with the right real-time intelligence.

Advanced IP Defense closes this gap. By pairing cloud-scale intelligence with granular, context-aware attribute inspection, it delivers real-time zero trust enforcement to block attacker infrastructure outright at the network layer before they can compromise your environment.

Explore Advanced IP Defense along with our latest lineup of CDSS innovations in our technical webinar: Stop Threats Earlier: Eliminate Frontier AI Exposure and Block Attacker Infrastructure.

To see where Advanced IP Defense can protect your specific environment, contact your Palo Alto Networks representative. Or, contact us for an Advanced IP Defense Security Lifecycle Review (SLR) — a tailored assessment of your network-layer exposure.


Subscribe to Network Security Blogs!

Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more.