Cloudflare integrates Cloudforce One intelligence into WAF rules

๐กAutomate your security posture by using real-time threat intelligence directly in your WAF rules.
โก 30-Second TL;DR
What Changed
New cf.intel fields enable direct integration of threat intelligence into WAF rules.
Why It Matters
This update significantly reduces the time-to-protection for organizations facing targeted cyber threats. It empowers security teams to leverage enterprise-grade intelligence without complex manual configurations.
What To Do Next
Update your WAF firewall rules to include the new cf.intel fields to automatically block known malicious actors targeting your specific industry.
Key Points
- โขNew cf.intel fields enable direct integration of threat intelligence into WAF rules.
- โขAutomates protection against high-risk traffic from specific threat actors.
- โขAllows for real-time filtering based on targeted industry threat data.
๐ง Deep Insight
Web-grounded analysis with 10 cited sources.
๐ Enhanced Key Takeaways
- โขCloudforce One leverages Cloudflare's extensive global network, processing billions of requests daily, to generate real-time threat intelligence, including actionable Indicators of Compromise (IoCs) and event summaries with associated threat actor groups and their Tactics, Techniques, and Procedures (TTPs).
- โขThe underlying Cloudforce One threat events platform is built on Cloudflare Workers AI and utilizes SQLite-backed Durable Objects to store and dynamically scale threat events, which enables the WAF to perform constant-time (O(1)) lookups with near-zero latency (microseconds) against these datasets.
- โขCloudforce One offers different subscription tiers (Essentials, Advantage, Elite) that provide varying levels of access to threat events, custom insights from threat intelligence analysts, and brand protection services.
- โขThe integration allows for highly granular, real-time filtering within WAF rules based on specific threat actors, targeted industries, and even includes capabilities like on-demand sinkholes to disrupt active attacks.
- โขThreat intelligence feeds from Cloudforce One are designed for easy integration via STIX/TAXII into existing Security Operations Center (SOC) workflows and security products such as SIEM/SOAR, EDR/XDR, and other Threat Intelligence Platforms (TIPs).
๐ ๏ธ Technical Deep Dive
- The integration utilizes new
cf.intelfields within Cloudflare WAF rules to directly incorporate threat intelligence. - Threat intelligence datasets are compressed into a high-performance format and distributed globally across all Cloudflare data centers.
- The Cloudflare WAF executes an O(1) constant-time lookup against these local datasets, ensuring that latency overhead remains effectively zero (measured in microseconds), regardless of the number of indicators.
- The Cloudforce One threat events platform is built on Cloudflare Workers AI and uses SQLite-backed Durable Objects for scalable and dynamic storage of observed threat events.
- Cloudforce One provides actionable Indicators of Compromise (IoCs) and event summaries, which are structured similarly to STIX2 sighting objects, offering contextual information and mapping to the MITRE ATT&CK framework.
- Threat intelligence feeds are designed to be operationalized through direct STIX/TAXII integrations into various security tools, including SIEM/SOAR platforms, EDR/XDR solutions, and other firewalls.
๐ฎ Future ImplicationsAI analysis grounded in cited sources
โณ Timeline
๐ Sources (10)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events โ
๐Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: Cloudflare Blog โ


