ATP is a feature that for the 9.2 release mainly focuses on C&C/botnet related threats and updates itself frequently by intel through our Sophos Labs. It's not much of a manually configurable blackhole for now, I'm afraid...
We'll investigate the options for extending it by the requested functionality, so.