<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: application control categories in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/268053#M53509</link>
    <description>&lt;P&gt;I would recommend adding either both of these for exclusively blocking a domain (none regex custom application):&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;webhook.site&lt;/CODE&gt;&lt;BR /&gt;www.webhook.site&lt;/PRE&gt;
&lt;P&gt;Or this for blocking both the domain and its subdomains:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;*webhook.site
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the main topic -&lt;/P&gt;
&lt;P&gt;If there are many URLs / Domains / IPs we need to block (and maintain &amp;amp; update the list), then IoC feeds or External Network Feeds would be best approach.&lt;/P&gt;
&lt;P&gt;For a smaller list of just URLs - a custom application object would suffice.&lt;/P&gt;
&lt;DIV&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk165094" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk165094: Best Practices -&amp;nbsp;&lt;STRONG&gt;Custom&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Applications&lt;/STRONG&gt;/Sites for&amp;nbsp;&lt;STRONG&gt;Application&lt;/STRONG&gt;&amp;nbsp;Control and URL Filtering&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="result-properties-wrapper"&gt;
&lt;DIV&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;R81.20 Quantum Security Management Administration Guide -&amp;nbsp;&lt;STRONG&gt;External&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Network&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Feeds&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="result-properties-wrapper"&gt;
&lt;DIV&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk132193: What is the "&lt;STRONG&gt;Custom Intelligence Feeds&lt;/STRONG&gt;" feature?&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jan 2026 13:17:29 GMT</pubDate>
    <dc:creator>Roslany</dc:creator>
    <dc:date>2026-01-21T13:17:29Z</dc:date>
    <item>
      <title>application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/267935#M53503</link>
      <description>&lt;P&gt;Has anyone tried to create a category for unallowed domains, like webhook.site?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem" target="_blank" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem&lt;/A&gt;&amp;nbsp; &amp;nbsp;We're blocking traffic to the domain webhook.site currently.&amp;nbsp; &amp;nbsp;Rather than maintaining a rule getting 0 hits, is there an application control category to block traffic to webhook.site?&amp;nbsp; &amp;nbsp;How do you look up to see if an IP or domain falls into an already existing category?&lt;/P&gt;
&lt;P&gt;Non-authoritative answer:&lt;BR /&gt;Name: webhook.site&lt;BR /&gt;Addresses: 2a01:4f8:121:114d::2&lt;BR /&gt;2a01:4f8:121:11a5::2&lt;BR /&gt;178.63.67.153&lt;BR /&gt;178.63.67.106&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 15:30:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/267935#M53503</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2026-01-20T15:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/267967#M53504</link>
      <description>&lt;P&gt;Going custom objects is probably the path here purely from a URLF perspective.&lt;/P&gt;
&lt;P&gt;Last i looked at this it was more a case of a legitimate online service being misused meaning it potentially falls outside the normal use case of URLF based on categories alone.&lt;/P&gt;
&lt;P&gt;Suspect it would fit into Computers / Internet / Business but you can check it here:&amp;nbsp;&lt;A href="https://usercenter.checkpoint.com/ucapps/urlcat/" target="_blank" rel="noopener"&gt;https://usercenter.checkpoint.com/ucapps/urlcat/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 00:29:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/267967#M53504</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-01-21T00:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/267968#M53505</link>
      <description>&lt;P&gt;Hey Dan,&lt;/P&gt;
&lt;P&gt;Here is what MS copilot gave me. This is on "deep think" setting, whatever that means lol&lt;/P&gt;
&lt;P&gt;***************************&lt;/P&gt;
&lt;DIV&gt;
&lt;H1&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Check Point — Custom Application Control Category&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;Here is a ready‑to‑paste definition for Check Point:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;Objects → Object Explorer → Application Categories&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;New Category&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Name it:&lt;BR /&gt;&lt;STRONG&gt;Blocked Callback Domains (Internal Security)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Add Custom Applications &amp;amp; URLs → &lt;STRONG&gt;New → Application/Site&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Add these entries:&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE&gt;&lt;CODE&gt;webhook.site
*.webhook.site
emailhook.site
*.emailhook.site
dnshook.site
*.dnshook.site
178.63.67.153
178.63.67.106
168.119.249.101
2a01:4f8:121:114d::2
2a01:4f8:121:11a5::2&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 21 Jan 2026 00:34:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/267968#M53505</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-21T00:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/267973#M53506</link>
      <description>&lt;P&gt;Here is what url lookup shows:&lt;/P&gt;
&lt;H1 class="sc-ggWZvA iDIRnp"&gt;URL Categorization&lt;/H1&gt;
&lt;DIV class="sc-fhHczv fhpPwc"&gt;For:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="sc-hvigdm eyCmxl" title="http://webhook.site"&gt;&amp;nbsp;&lt;A href="http://webhook.site" target="_blank"&gt;http://webhook.site&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;Current&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Categories:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Computers / Internet, Low Risk&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;SECTION class="sc-fszimp egryKS"&gt;
&lt;DIV class="sc-jaXbil kqsMLn"&gt;
&lt;P&gt;Computers / Internet&lt;/P&gt;
&lt;P&gt;This category is intended to cover websites related to computing software and hardware, as well as Internet and technology-related companies. This includes, but is not limited to vendors, product reviews, and deployment and maintenance of software and hardware. This also includes addons such as scripts, plugins, drivers, peripherals, and other equipment used in conjunction with computers and networks. Examples: &lt;A href="http://www.archive.org" target="_blank"&gt;http://www.archive.org&lt;/A&gt;, &lt;A href="http://www.verisign.com" target="_blank"&gt;http://www.verisign.com&lt;/A&gt;, &lt;A href="http://www.limewire.com" target="_blank"&gt;http://www.limewire.com&lt;/A&gt;, &lt;A href="http://www.w3schools.com" target="_blank"&gt;http://www.w3schools.com&lt;/A&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="sc-jaXbil kqsMLn"&gt;
&lt;P&gt;Low Risk&lt;/P&gt;
&lt;P&gt;Applications and Websites that are potentially non business related yet low risk.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 21 Jan 2026 02:16:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/267973#M53506</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-21T02:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/268038#M53507</link>
      <description>&lt;P&gt;I made a recommendation that it gets re-categorized to malicious sites based on&amp;nbsp;&lt;A href="https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem" target="_blank"&gt;Widespread Supply Chain Compromise Impacting npm Ecosystem | CISA&lt;/A&gt;&amp;nbsp; &amp;nbsp;Maybe, check point can create a new category like application control jail.&amp;nbsp; For temporary sites that are out of compliance.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 12:58:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/268038#M53507</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2026-01-21T12:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/268039#M53508</link>
      <description>&lt;P&gt;Always good idea to send a request.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 13:03:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/268039#M53508</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-21T13:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/268053#M53509</link>
      <description>&lt;P&gt;I would recommend adding either both of these for exclusively blocking a domain (none regex custom application):&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;webhook.site&lt;/CODE&gt;&lt;BR /&gt;www.webhook.site&lt;/PRE&gt;
&lt;P&gt;Or this for blocking both the domain and its subdomains:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;*webhook.site
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the main topic -&lt;/P&gt;
&lt;P&gt;If there are many URLs / Domains / IPs we need to block (and maintain &amp;amp; update the list), then IoC feeds or External Network Feeds would be best approach.&lt;/P&gt;
&lt;P&gt;For a smaller list of just URLs - a custom application object would suffice.&lt;/P&gt;
&lt;DIV&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk165094" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk165094: Best Practices -&amp;nbsp;&lt;STRONG&gt;Custom&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Applications&lt;/STRONG&gt;/Sites for&amp;nbsp;&lt;STRONG&gt;Application&lt;/STRONG&gt;&amp;nbsp;Control and URL Filtering&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="result-properties-wrapper"&gt;
&lt;DIV&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;R81.20 Quantum Security Management Administration Guide -&amp;nbsp;&lt;STRONG&gt;External&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Network&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Feeds&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="result-properties-wrapper"&gt;
&lt;DIV&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk132193: What is the "&lt;STRONG&gt;Custom Intelligence Feeds&lt;/STRONG&gt;" feature?&lt;/SPAN&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 13:17:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/268053#M53509</guid>
      <dc:creator>Roslany</dc:creator>
      <dc:date>2026-01-21T13:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/268057#M53510</link>
      <description>&lt;P&gt;Im with you, totally agree. I just have bad habit of doing *domain* to exempt these things, but of course thats not close to optimal solution, I just found myself too many times in the past troubleshooting these things for hours on end.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 13:23:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/268057#M53510</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-21T13:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/269538#M53511</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I'm the founder of Webhook.site. I found this via Google Alerts. In case you didn't know, we have thousands of paying customers using Webhook.site for testing webhooks, building workflows and other purposes, so it is worrying that some of our users are seeing their access blocked. Here's some more info about our company:&amp;nbsp;&lt;A href="https://docs.webhook.site/#what-is-webhooksite" target="_blank"&gt;https://docs.webhook.site/#what-is-webhooksite&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Where can we report this false positive? Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 09:03:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/269538#M53511</guid>
      <dc:creator>SimonFredsted</dc:creator>
      <dc:date>2026-02-03T09:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/269551#M53512</link>
      <description>&lt;P&gt;To contrary the access is not blocked by default, some community members are requesting better ways of blocking hosted elements should they choose to.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 11:19:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/269551#M53512</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-02-03T11:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: application control categories</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/273377#M104118</link>
      <description>&lt;P&gt;Hi Simon, Why did it get flagged here then?&amp;nbsp;&amp;nbsp;&lt;A href="https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem" target="_blank"&gt;Widespread Supply Chain Compromise Impacting npm Ecosystem | CISA&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2026 16:39:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/application-control-categories/m-p/273377#M104118</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2026-03-13T16:39:05Z</dc:date>
    </item>
  </channel>
</rss>

