How to block ultrasurf using Cisco FTD via FMC

I am trying to block ultrasurf application using my FMC any ideas on how to do it?

I found something about using certificate to push through the browser then this certificate will be included in my FMC policy to be blocked.

If it’s not in the app list can you block the url or ports provided they are not common? Worst case can you get an ip or network list for a custom threat list?

We use Cisco umbrella dns and block categories there too if you don’t have web categories in firepower, but that is super useful and $$$ too.

I would think it would be in the anonymizer or vpn categories y.