logo

Always-on detections: eliminating the WAF “log versus block” trade-off

ID: a027c2b4-ddac-5782-8440-9d50a41798b0

STIX ID: report--a027c2b4-ddac-5782-8440-9d50a41798b0

Feed Name: Cloudflare Blog

Date Published: 2026-03-04

Date Updated: 2026-04-27

Author: Daniele Molteni

...
...

Cloudflare announces Attack Signature Detection — an always-on, detection-only signature framework that inspects every proxied request, tags matches with metadata (cf.waf.signature.request.*) and feeds Security Analytics to simplify safe onboarding and policy creation — and previews Full-Transaction Detection, which correlates requests and responses to reduce false positives and detect successful exploits, data exfiltration, and misconfigurations (with response fields cf.waf.signature.response.*). The document details signature categories/confidence levels, analytics-driven tuning and rule creation workflows, and the availability status (Attack Signature in Early Access; Full-Transaction under development).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.