A knowledge base article about How to block outgoing traffic to known malicious hostnames provided by the UC Berkeley IT Service Hub - Knowledge Portal
These instructions deal with how to create a custom “Anti-Spyware” profile to block malicious hostnames (i.e. Fully Qualified Domain Names) using the campus list of malicious hostnames derived from trusted sources. For most firewall administrators these steps will not be necessary as the existing feeds of malicious FQDNs are already in all of the Anti-Spyware profiles created by ISP and these are the recommended profiles for administrators to use. Those recommended profiles all start with “ucbsec-” and their location in the Panorama hierarchy is “Global.” If an administrator needs to customize one the best option is to clone an existing rule in which case the malicious hostname blocking will also be cloned. The following instructions should only be necessary when a completely new “Anti-Spyware” profile is being created or an administrator is creating a profile from one of the Palo Alto “Predefined” profiles since they would lack our local customization.
At this point the new Anti-Spyware profile is available to add to any firewall rules. If the custom profile is only to be used for individual hosts then it’s fine to add it and any other profiles to the rule from its “Actions” tab and, using the Profile Type “Profiles”, to set all of the individual profiles (AntiVirus, Vulnerability Protection, etc.) individually. However, if this selection of profiles is to be used across multiple devices, then it is recommended to create a Profile Group that can be applied to a rule so that all of the individual Profiles are set consistently with only one Profile Group selection. If this profile should be used for all rules created on the vsys, it can be used in the default profile group.