INTEGRITY Cloudflare Docs

Cloudforce One

Cloudforce One is Cloudflare's Threat Intelligence Platform (TIP). It collects and correlates threat data from Cloudflare telemetry, then surfaces that data as visualizations, automated rules, and analyst-reviewed intelligence.

Security Operations Center (SOC) teams use Cloudforce One to investigate threats, track adversaries, and take action — such as pushing firewall rules or exporting indicators.

Access Cloudforce One

To access Cloudforce One:

  1. In the Cloudflare dashboard, go to the Threat intelligence page.

    Go to Threat intelligence ↗

You can also use Cloudforce One via the REST API.

The Threat Intelligence page contains four sections:

Analyze threat events

Threat events represent Cloudflare telemetry and threat actor activity observed on the Cloudflare network. Use threat events to investigate threats targeting your organization or your industry.

To access threat events, go to the Threat intelligence page in the Cloudflare dashboard.

Go to Threat intelligence ↗

You can also access threat events via the API.

Cloudforce One customers have access to the following datasets:

Identify the adversary

The Cloudflare dashboard provides visualizations that include:

Search for indicators

Search across global datasets for specific indicators, including:

Create WAF Rules and receive notifications

Use Cloudy to analyze threat events

You can use Cloudy, Cloudflare's AI Agent, to receive an analysis and summary of threat events.

To analyze threat events using Cloudy:

  1. In the Cloudflare dashboard, go to the Threat intelligence page.

    Go to Threat intelligence ↗
  2. Go to Threat Events > Analyze with Cloudy.

Cloudy will show you the top threat events, analyze them, and give you a summary of threat events. You can also decide to receive an analysis based on Attacker, Indicator, and more. For example, you can enter "Give me a summary of threat events for ABC Attacker". Cloudy will then summarize threat events for ABC attacker.

Submit RFIs

To submit RFIs (Request for Information):

  1. In the Cloudflare dashboard, go to the Threat Intelligence page.

    Go to Threat intelligence ↗
  2. Select Requests for Information.

  3. Select New Request.

  4. Fill in the required fields, then select Save.

List of RFI types

The following request types are available when you submit a Request for Information:

Once you select Save, the dashboard will display an overview of the shared information consisting of:

The Responses section allows you to add clarifying questions and comments.

To view your RFI, select Cloudforce One Requests on the sidebar, locate your RFI, then select View. From here, you can also choose to edit your existing RFI by selecting Edit.

To delete your RFI, the status must be Open. Go to the RFI you want to delete, and select Delete. On the pop-up, select Delete to confirm deletion. Once Cloudflare accepts and begins processing RFIs, you will not be able to delete RFIs.

Upload and download attachment

You can also choose to upload and download an attachment.

Under Attachments, select the file you want to upload, then select Save.

To download an attachment, select Download on the attachment.

Improve your security posture or recover from a past incident

Use Cloudforce One to improve your security posture or recover from a past incident.

  1. In the Cloudflare dashboard, go to Application security > Incident Response.

  2. Choose service: Select one of the services.

  3. Provide request details:

Request help for active attack

If you want to stop an active cyber attack, you can request assistance via the Cloudflare dashboard.

  1. In the Cloudflare dashboard, go to the Account home page and select your account.
Go to Account home ↗
  1. On the top bar, select Support > Get help > Under attack.
  2. Under Request help to stop active cyberattacks, select Request help.
  3. The dashboard will show you a pop-up where you will need to enter and confirm your phone number.
  4. Once you have entered your phone number, select Confirm number and request help. Requesting help from the dashboard will page an incident responder and you can expect a call-back as soon as possible. We advise you to wait for the call-back, and only use the phone-line in case you have not heard back from the team within 10 minutes.