INTEGRITY Cloudflare Docs

Threat intelligence

The threat intelligence detection matches incoming requests against indicators in the Cloudforce One threat intelligence database. The detection matches on client IP address. If the IP was involved in threat activity in the past seven days, Cloudflare populates threat intelligence fields you can use in WAF rule expressions.

You can use these fields in custom rules and rate limiting rules to match on:

You can review matches in Security Analytics to see which threat actors and campaigns are reaching your application.

Data freshness

The threat intelligence database reflects a rolling seven-day window:

Availability

Requires an active Cloudforce One subscription. Contact your account team for access.

The WAF must be enabled on your zone before threat intelligence fields can be used in rule expressions.

More resources