๐Ÿ›ก๏ธStalecollected in 2h

Cloudflare integrates Cloudforce One intelligence into WAF rules

Cloudflare integrates Cloudforce One intelligence into WAF rules
PostLinkedIn
๐Ÿ›ก๏ธRead original on Cloudflare Blog

๐Ÿ’กAutomate your security posture by using real-time threat intelligence directly in your WAF rules.

โšก 30-Second TL;DR

What Changed

New cf.intel fields enable direct integration of threat intelligence into WAF rules.

Why It Matters

This update significantly reduces the time-to-protection for organizations facing targeted cyber threats. It empowers security teams to leverage enterprise-grade intelligence without complex manual configurations.

What To Do Next

Update your WAF firewall rules to include the new cf.intel fields to automatically block known malicious actors targeting your specific industry.

Who should care:Enterprise & Security Teams

Key Points

  • โ€ขNew cf.intel fields enable direct integration of threat intelligence into WAF rules.
  • โ€ขAutomates protection against high-risk traffic from specific threat actors.
  • โ€ขAllows for real-time filtering based on targeted industry threat data.

๐Ÿง  Deep Insight

Web-grounded analysis with 10 cited sources.

๐Ÿ”‘ Enhanced Key Takeaways

  • โ€ขCloudforce One leverages Cloudflare's extensive global network, processing billions of requests daily, to generate real-time threat intelligence, including actionable Indicators of Compromise (IoCs) and event summaries with associated threat actor groups and their Tactics, Techniques, and Procedures (TTPs).
  • โ€ขThe underlying Cloudforce One threat events platform is built on Cloudflare Workers AI and utilizes SQLite-backed Durable Objects to store and dynamically scale threat events, which enables the WAF to perform constant-time (O(1)) lookups with near-zero latency (microseconds) against these datasets.
  • โ€ขCloudforce One offers different subscription tiers (Essentials, Advantage, Elite) that provide varying levels of access to threat events, custom insights from threat intelligence analysts, and brand protection services.
  • โ€ขThe integration allows for highly granular, real-time filtering within WAF rules based on specific threat actors, targeted industries, and even includes capabilities like on-demand sinkholes to disrupt active attacks.
  • โ€ขThreat intelligence feeds from Cloudforce One are designed for easy integration via STIX/TAXII into existing Security Operations Center (SOC) workflows and security products such as SIEM/SOAR, EDR/XDR, and other Threat Intelligence Platforms (TIPs).

๐Ÿ› ๏ธ Technical Deep Dive

  • The integration utilizes new cf.intel fields within Cloudflare WAF rules to directly incorporate threat intelligence.
  • Threat intelligence datasets are compressed into a high-performance format and distributed globally across all Cloudflare data centers.
  • The Cloudflare WAF executes an O(1) constant-time lookup against these local datasets, ensuring that latency overhead remains effectively zero (measured in microseconds), regardless of the number of indicators.
  • The Cloudforce One threat events platform is built on Cloudflare Workers AI and uses SQLite-backed Durable Objects for scalable and dynamic storage of observed threat events.
  • Cloudforce One provides actionable Indicators of Compromise (IoCs) and event summaries, which are structured similarly to STIX2 sighting objects, offering contextual information and mapping to the MITRE ATT&CK framework.
  • Threat intelligence feeds are designed to be operationalized through direct STIX/TAXII integrations into various security tools, including SIEM/SOAR platforms, EDR/XDR solutions, and other firewalls.

๐Ÿ”ฎ Future ImplicationsAI analysis grounded in cited sources

Cloudflare will further enhance its WAF with more granular, AI-driven threat detection capabilities.
The integration of Cloudforce One, built on Workers AI, and the existing use of machine learning for threat detection suggest a continued focus on advanced, automated threat mitigation within the WAF.
The direct integration of threat intelligence will lead to a reduction in manual security operations for Cloudflare customers.
Automating real-time blocking based on threat actor and industry-specific intelligence directly within WAF rules significantly reduces the need for manual rule creation and continuous updates by security teams.
Cloudflare will expand the types of proprietary datasets integrated into Cloudforce One for WAF rules.
Cloudflare has explicitly stated plans to incorporate additional event types from its Zero Trust Gateway, Zero Trust Email Security, and other proprietary datasets into the Cloudforce One threat events platform.

โณ Timeline

2009-07
Cloudflare founded by Matthew Prince, Lee Holloway, and Michelle Zatlyn.
2010-09
Cloudflare publicly launched at TechCrunch Disrupt, offering DNS-based security and performance services.
2013-08
Cloudflare launched a new, traditional rules-based Web Application Firewall (WAF) to complement its existing heuristics-based system.
2022-02
Cloudflare acquired Area 1 Security, a company specializing in phishing attack prevention, with co-founder Blake Darchรฉ later heading Cloudforce One.
2022-06
Cloudflare introduced Cloudforce One as its new threat operations and research team, focused on tracking and disrupting threat actors.
2025-03
Cloudflare launched the Cloudforce One threat events platform, providing real-time intelligence on cyberattacks, built on Cloudflare Workers AI.

๐Ÿ“Ž Sources (10)

Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.

  1. cloudflare.net
  2. cloudflare.com
  3. cloudflare.com
  4. cloudflare.com
  5. globalsecuritymag.com
  6. cloudflare.com
  7. cloudflare.com
  8. cloudflare.com
  9. cloudflare.com
  10. radware.com
๐Ÿ“ฐ

Weekly AI Recap

Read this week's curated digest of top AI events โ†’

๐Ÿ‘‰Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: Cloudflare Blog โ†—