Docs / Policies & Filtering / Security categories
Browse Policies & Filtering
Policies & Filtering

Security categories

Threat-focused category reference. The Security categories block known malicious infrastructure: malware, phishing, command-and-control, compromised hosts, and more.

Updated Aug 23, 2025 • 2 min read

The Security tab in a policy toggles threat-focused blocking. Unlike the content categories (which manage what users are allowed to access), security categories block known malicious infrastructure. Most production policies enable all of them.

CategoryWhat it blocks
AdwareSoftware that displays unwanted advertisements to generate revenue. May appear as banners or pop-ups during install. Tracks personal information that can be sold to third parties.
Infected HostsCompromised hosts that act as distribution points for malicious software or are used in DDoS attacks.
Malicious ScriptsDomains hosting obfuscated or hidden JavaScript that can modify a user’s system and compromise security.
MalwareDomains hosting general malware: ransomware, keyloggers, worms, trojans, spyware. Also blocks known ransomware command-and-control (C2) domains.
PhishingKnown or suspected phishing domains, financial fraud, credential theft, identity theft.
VirusesDomains associated with known computer viruses.

[!TIP] The Security categories are independent of Content and Applications. A typical baseline policy turns on every Security category by default, while Content and Applications are tuned per audience.

Was this article helpful?
Still stuck? Open a ticket and we'll follow up by email.
Open a ticket
Last updated Aug 23, 2025