The Advanced URL Filtering Operator Dashboard is a subscription-specific view
that delivers a centralized hub for web threat activity, offering immediate and
actionable insights. Interactive widgets surface critical efficacy metrics—such
as day-zero malicious URL detections, daily threat trends, and top risky
domains—providing an intuitive starting point for deeper drill-down analysis. By
utilizing contextual data on users, devices, and policies, security teams can
detect, investigate, and remediate web-based threats more efficiently than ever
before.
Flexible Data Filtering: Customize the dashboard time range (from the
last 15 minutes up to 45 days, or define a custom range) and apply general
filters to isolate specific datasets.
Interactive Widgets: Interact directly with individual widgets to filter
data, reorder columns, zoom, view raw data, export as CSV, and toggle legends
and labels.
Key Visibility Metrics
The dashboard provides granular visibility into the following areas:
- Key statistics—Total URL requests, total malicious URL requests
detected, malicious IP addresses, and zero-day threats (malicious URLs
detected in real time), providing an at-a-glance assessment of URL
filtering efficacy and the scale of real-time protection.
- Daily threat trends—Daily threat activity over time including
real-time detections and phishing attempts. Spikes indicate anomalies
and need investigation.
- URL categorization—URL request distribution (the balance of safe
versus risky traffic) and breakdown of malicious URL categories (such as
command-and-control, phishing, grayware, and ransomware).
- Domain analysis—Top visited domains overall and top visited
malicious domains, identifying the external infrastructure that attackers
are utilizing.
- User and firewall attribution—Top users accessing malicious URL
categories and top firewalls contributing to malicious traffic,
pinpointing the human and network hotspots driving risk.
- Policy effectiveness—Security rules triggered most often,
indicating policy coverage and identifying opportunities for
optimization.
Operational Use Cases
Leverage the dashboard data to drive the following investigative and operational
initiatives:
- Scope the initial attack vector—Modern campaigns like Zloader
begin at the web gateway. Identify immediate spikes in real-time
detection and phishing attempts. Zero-day threat counts show malicious
URLs detected in real time that represent proactive prevention of novel,
never-before-seen attacks before they enter your network.
- Identify human hotspots—Pinpoint users accessing the most
malicious URL categories. This enables you to move from general blocking
to targeted intervention (such as security training or network isolation)
for high-risk users who are repeat offenders.
- Identify infrastructure hotspots—Identify the external
infrastructure attackers are utilizing, and identify enforcement points
that may be misconfigured or serving high-risk network segments, allowing
targeted policy tightening.
- Investigate and apply targeted blocks—Understand the nature of
threats by category (C2, phishing, grayware, ransomware) and
cross-reference with risky domains to zero in on high-risk areas and
apply targeted URL category or domain blocks in your security
policies.
- Confirm safety and investment value—Compare total URLs versus
malicious alongside zero-day detections and daily trends to demonstrate
ROI. These metrics help CISOs confidently answer whether the
organization is protected and whether the Advanced URL Filtering
investment is delivering value.