Unleashing improved context for threat actor activity with our Cloudforce One threat events platform
ID: 1b20b5fc-576d-5bb9-9755-49dd554c4378
STIX ID: report--1b20b5fc-576d-5bb9-9755-49dd554c4378
Feed Name: Cloudflare Blog
Cloudflare introduces a Cloudforce One threat events platform that transforms massive HTTP/DNS telemetry into context-rich, real-time threat events mapped to MITRE ATT&CK and kill chain stages, accessible via dashboard and API for investigation and filtering. Built on Cloudflare Workers and Durable Objects for scalable, customizable datasets, the platform aims to give defenders actionable context (including IoCs) and strategic views like attacker timelines; an example highlights curating verified infrastructure tied to the Black Basta group. Early user validation from a Fortune 20 TI team is positive, and forthcoming enhancements include deeper visualizations, SIEM integrations, and expanded datasets (e.g., WAF, Zero Trust, Email Security).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
