MikhbarMIKHBAR
Artificial Intelligence

Cloudflare Introduces Threat Signals for Free

Cloudflare is expanding access to its Cloudforce One Threat Events Platform to every account while introducing Threat Signals to parse open-source threat reporting automatically.

Cloudflare Introduces Threat Signals for Free

Automating Open-Source Threat Intelligence

Organizations can now scale threat intelligence expertise in the same way they scale infrastructure, according to a recent announcement from the Cloudflare Blog. Threat intelligence analysts and network defenders have long automated the ingestion of structured threat feeds to enrich systems like a SIEM or WAF. However, the more difficult work has consistently involved unstructured reporting—turning complex research posts into indicators tools can use without losing critical context.

To address this challenge, Cloudflare is launching Threat Signals to every Cloudflare account. The system turns chosen open-source reporting into actionable intelligence by utilizing agentic skills to summarize reports, surface key context, extract and normalize indicators of compromise, and apply tags within a private, account-scoped dataset.

Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account
Image related to the report from Cloudflare Blog · Source: Cloudflare Blog

Expanding Access to Cloudforce One

Alongside the launch of Threat Signals, Cloudflare is expanding access to the Cloudforce One Threat Events Platform, its core threat intelligence offering, making it available to all Cloudflare accounts for free. Every account now receives API and dashboard access to Threat Signals alongside the ability to select one RSS feed.

Additionally, accounts receive a private dataset built from the selected RSS feed, tailored to reporting requirements and stored for up to 30 days. Users also gain API and dashboard access to the Threat Events Platform to investigate events, indicators, and tags tied to their private dataset.

A view of Threat Signals displaying collected RSS feeds
A view of Threat Signals displaying collected RSS feeds · Source: Cloudflare Blog

Workflow and Processing Pipeline

The Threat Signals system uses RSS to monitor open-source reporting tailored to an organization. Users can add a feed, assign a name and category, and configure checking frequency while supporting RSS 2.0, Atom, and RSS 1.0/RDF specifications. Each selected feed enters a Workflow that periodically polls for new articles.

Cloudflare utilizes Browser Run's Markdown quick action to fetch and clean article text into a readable markdown format, which is then stored in R2. The text passes through an indicator of compromise extractor and a set of default Cloudforce One-defined skills to summarize content, apply tags based on configuration, and add indicator contextualization.

Threat Signal article summarized with key points and contextualized indicators
Threat Signal article summarized with key points and contextualized indicators · Source: Cloudflare Blog

Enterprise Extensions and Policy Application

Customers subscribed to Essentials, Advantage, and Elite tiers can extend the standard offering. These enterprise capabilities include an expanded number of RSS feeds, access to Cloudforce One proprietary threat intelligence datasets, and the ability to generate custom agentic skills.

Furthermore, enterprise customers gain higher storage options for Threat Signals derived open-source reporting and the ability to build custom rules. Analysts can take extracted indicators backed by a threat event and instantly apply them to a WAF policy to secure applications and infrastructure.

Sources

  • Cloudflare BlogIntroducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account

Continue chronologically

Related entity coverage