The malicious-url enable command enables the malicious URL detection function of APT defense.
The undo malicious-url enable command disables the malicious URL detection function of APT defense.
The malicious URL detection function of APT defense is disabled by default.
When this function is enabled, the device matches traffic against cached malicious URLs. If the traffic matches a malicious URL, the device blocks the URL, and the traffic does not need to be sent to the sandbox for inspection. If the traffic does not match a malicious URL, the traffic is sent to the sandbox for inspection. The malicious URLs cached in the device are generated based on the inspection results of the sandbox.