According to Jordan in support, the default policy that's created with a new account should be blocking things like malware and botnets. We just created a new account for testing, and none of the threat categories were blocked.