Predefined EDL Reference
The following predefined EDLs deliver curated subsets of Advanced IP Defense
intelligence through the antivirus content package.
| EDL Name | EDL Object Name | Description |
| C2 Infrastructure | panw-aipd-c2-infra-ip-list | IP addresses used for Command and Control (C2) communications,
including those hosting C2 services or resolved from known C2
domains. Block this list for both inbound and outbound traffic to
prevent malicious activity. |
| Hardcoded in Malware | panw-aipd-in-malware-ip-list | IP addresses embedded in malware samples or exploitation shellcode.
Block this list for both inbound and outbound traffic to prevent
communication with hardcoded malicious endpoints. |
| Commercial VPNs | panw-aipd-vpn-ip-list | IP addresses owned by commercial Virtual Private Network (VPN)
service providers. Traffic from VPNs can obscure malicious origins.
Block this list for inbound traffic to prevent attack attempts from
commercial VPN services. |
| Proxy Services | panw-aipd-proxies-ip-list | IP addresses hosting suspicious open (no authentication required) or
private (authentication required) proxy services (such as HTTP,
SOCKS, OpenVPN) not associated with known, legitimate commercial VPN
providers. These services mask attacker identity and are a common
source of malicious activity. Block this list for inbound
traffic. |
| Scanner & Brute Force | panw-aipd-scanning-ip-list | IP addresses actively engaged in malicious network scanning or
automated brute-force attacks. Block this list for inbound traffic
to prevent reconnaissance and initial access attempts from reaching
your systems. Known, non-malicious scanners (such as shodan.io and
Censys) are excluded. |
| Exposed Vulnerable Services | panw-aipd-vuln-svcs-ip-list | IP addresses hosting publicly reachable services vulnerable to
known CVEs or exploits (such as exposed RDP, SMB, VNC, or unpatched
web servers). Attackers use these compromised systems as launching
points for further attacks. Block this list for inbound traffic to
protect against exploitation attempts originating from these
hosts. |
The antivirus content package delivers the same set of EDL files to all platforms. At
install time, the content update automatically trims each list to the appropriate
size based on your platform's hardware capacity. You do not need to select a tier
manually; the content update determines the correct size for your enforcement
point.
If an IP has multiple attributes, it appears in only one EDL based on severity
priority (highest to lowest): C2 infrastructure, Hardcoded in malware, VPN,
Proxies, Scanner and brute-force, Exposed vulnerable services.
Each EDL ranks IPs by priority in descending order. If platform capacity requires
truncation, the list retains the highest-priority entries.