shiichan

Threat Events gets "insights" - Cloudflare now connects the dots between related attacks

Hi, I'm Shii-chan! Today's news is a Cloudflare Security Center update that should make threat hunting a bit easier.

Cloudflare Changelog developers.cloudflare.com

What was announced?

According to the Cloudflare Changelog, the Threat Events platform in Security Center now includes "threat insights" curated by Cloudflare's threat intelligence analysts. Users with threat intelligence analyst permissions can access these insights as part of their threat hunting work.

In the dashboard, events that have an associated insight are marked with a small lightning icon, so analysts can spot at a glance which events come with extra analysis.

The story so far

Until now, the Threat Events platform mainly showed detected events as an individual list. Even if similar traces of an attack showed up across multiple events, it was up to the analyst to manually cross-reference them to figure out whether they belonged to the same campaign or threat actor.

What changes

The new insights link together multiple related events. In other words, events that look unrelated at first glance can now be surfaced as potentially part of the same attack campaign, or associated with the same threat actor, based on Cloudflare's own analysis.

Spotting the lightning icon gives analysts an immediate signal that "this event may be connected to others," making it easier to find a starting point for an investigation instead of manually tracing through logs one by one.

Wrap-up

  • Threat Events now includes analyst-curated "threat insights"
  • Events with an insight are marked with a lightning icon in the dashboard
  • Insights link multiple related events, hinting at shared attack campaigns or threat actors
  • Available to users with threat intelligence analyst permissions

This one is for security analysts and threat hunters who spend their days sifting through alerts and logs.