Skip to content
ThreatSTOP for AWS Blog

Stop threats before the connection is ever made.

Almost every attack starts with a DNS lookup: ransomware calling home, phishing loading its fake page, malware fetching instructions. Block the lookup and the attack never starts. DNS Defense turns the DNS server you already run into that checkpoint, so malware, ransomware, phishing, and command-and-control callbacks never reach your network.

DNS resolution
Resolver 01
Interface preview: a live query feed with allow and block verdicts, as it appears in the ThreatSTOP console
14:22:03 api.stripe.com ALLOWED
14:22:05 cdn-c2-node8137.xyz command-and-controlBLOCKED
14:22:08 updates.microsoft.com ALLOWED
14:22:11 mail.google.com ALLOWED
14:22:14 secure-login-paypa1.com phishingBLOCKED
14:22:17 sync.dropbox.com ALLOWED
14:22:19 assets.cloudfront.net ALLOWED
14:22:22 locky-decrypt-pay.top ransomwareBLOCKED
14:22:25 telemetry.datadog.io ALLOWED
Every lookup checked against ThreatSTOP intelligence, in real time.

How protective DNS works.

Every outbound lookup is inspected before it resolves, so threats are stopped the moment a connection is attempted, long before anything reaches your network.

DNS LOOKUP THREATSTOP INSPECTION BEFORE IT RESOLVES MALICIOUS LOOKUP BLOCKED LEGITIMATE DOMAIN RESOLVES
Every outbound lookup is checked against ThreatSTOP intelligence before it resolves, so malicious domains are blocked while legitimate traffic resolves normally.

Security built into the layer where every connection begins.

Compatibility
Any DNS server
BIND, Windows DNS, Infoblox and more, with no new hardware to buy.
Intelligence
Curated intelligence
Over 900 threat intelligence sources, curated by people and machines for broad coverage.
Coverage
Blocks the kill chain
Command-and-control, phishing, malware, ransomware, and data exfiltration.
Reporting
Reporting built in
Clear reporting on every blocked threat and the device it came from.

An 80% drop in malware infections, 30 minutes to deploy.

Point your DNS at ThreatSTOP and you can be live in about half an hour, with no new hardware. Customers see malware infections fall by 80% once protective DNS is in place.

80%
reduction in malware infections after a 30-minute deploy
30 min
to deploy, with no new hardware to buy
0.002%
12-month false-positive rate

Start blocking threats at the DNS layer.

Turn your DNS into a security checkpoint in minutes. Request a trial or talk to an engineer.