icon-unified.svg
Experience Center

Adding Threat Categories

Threat categories group common threats (e.g., viruses, botnets, exploits) together, which can be detected and controlled by Zscaler's signature-based intrusion detection. In addition to the predefined threat categories provided by Zscaler, you can define custom threat categories and add custom IPS signature rules to them.

To add a custom threat category,

  1. Go to Policies > Cybersecurity > Inline Security > Custom IPS Signatures.
  2. Click the Threat Categories tab.
  3. Click Add Threat Category.

    The Add Threat Category window appears.

  4. In the Add Threat Category window:
    • Name: Provide a unique name for the threat category. The name can contain any characters, including spaces, within a character limit of 255.
    • Description: (Optional) Provide a description for the threat category. The description cannot exceed 255 characters.
  5. Click Save and activate the change.
Related Articles
About Network ServicesConfiguring Network ServicesModifying Predefined Network ServicesAbout Network Service GroupsConfiguring Network Service GroupsAbout Network ApplicationsAbout Network Application GroupsConfiguring Network Application GroupsAbout Application Service GroupsAbout Source IP GroupsConfiguring Source IP GroupsAbout Destination IP GroupsConfiguring Destination IP GroupsAbout DNS Application GroupsConfiguring DNS Application GroupsAbout IP PoolAbout Threat CategoriesAdding Threat CategoriesAbout EDNS Client Subnet (ECS) InjectionAdding EDNS Client Subnet (ECS) PrefixesAbout DNS GatewaysAdding DNS Gateways