Predefined EDL Reference
The following predefined EDLs deliver curated subsets of Advanced IP Defense
intelligence through the Anti-Virus content package.
| EDL Name | EDL Object Name | Description |
| C2 Infrastructure | panw-aipd-c2-infra-ip-list | IP addresses used for Command and Control (C2) communications,
including those hosting C2 services or resolved from known C2
domains. Blocking this list is recommended for both inbound and
outbound traffic to prevent malicious activity. |
| Hardcoded in Malware | panw-aipd-in-malware-ip-list | IP addresses embedded in malware samples or exploitation
shellcode. Blocking this list is recommended for both inbound and
outbound traffic to prevent communication with hardcoded malicious
endpoints. |
| Commercial VPNs | panw-aipd-vpn-ip-list | IP addresses owned by commercial Virtual Private Network (VPN)
service providers. As traffic from VPNs can obscure malicious
origins, blocking this list is recommended for inbound traffic to
prevent attack attempts. Ideal for organizations whose security
policies prohibit inbound connections from commercial VPN
services. |
| Proxy Services | panw-aipd-proxies-ip-list | IP addresses hosting suspicious open (no auth needed) or private
(auth needed) proxy services (such as HTTP, SOCKS, OpenVPN) that
are not associated with known, legitimate commercial VPN providers.
These services mask attacker identity and are a common source of
malicious activity, making blocking them recommended for inbound
traffic. |
| Scanner & Brute Force | panw-aipd-scanning-ip-list | IP addresses actively engaged in malicious network scanning or
automated brute-force attacks. Blocking this list is recommended for
inbound traffic to prevent reconnaissance and initial access attempts
from reaching your systems. Known, non-malicious scanners (such as
shodan.io and Censys) are excluded. |
| Exposed Vulnerable Services | panw-aipd-vuln-svcs-ip-list | IP addresses hosting publicly reachable services vulnerable to
known CVEs or exploits (such as exposed RDP, SMB, VNC, or unpatched
web servers). Attackers use these compromised systems as launching
points for further attacks, so blocking these is recommended for
inbound traffic to protect against exploitation attempts originating
from these hosts. |
The AV content package delivers the same set of EDL files to all platforms. At
install time, the content update automatically trims each list to the appropriate
size based on your platform's hardware capacity. You do not need to select a tier
manually — the content update determines the correct size for your enforcement
point.
If an IP has multiple attributes, it appears in only one EDL based on severity
priority (highest to lowest): C2 infrastructure, Hardcoded in malware, VPN,
Proxies, Scanner and brute-force, Exposed vulnerable services.
Each EDL ranks IPs by priority in descending order. If platform capacity requires
truncation, the list retains the highest-priority entries.