Who's behind that attack? Cloudflare's Threat Actor Profiles unmask them!
Heya, it's Shiichan! Today I found a security update that got me excited. It makes hunting down the "culprit" behind a blocked attack so much easier.
Cloudflare ChangelogWhat was announced?
On Cloudflare's Changelog, they announced that Security Center added Threat Actor Profiles to the Threat Events dashboard. Now you can pivot straight from a blocked attack event to the "Who, Why, and How" of the adversary behind it.
The story so far
Until now, security teams had a "visibility gap." Even when an attack was blocked, it was hard to tell whether it was just a random bot or a sophisticated APT (advanced persistent threat) campaign specifically targeting your industry. To find out, you had to leave the dashboard and dig through external OSINT feeds or stale threat reports... kind of a hassle.
What changes
Threat Actor Profiles bring Cloudforce One's deep adversary research right into your investigation workflow. And because Cloudflare sees about 20 % of web traffic in real time, the profiles show active malicious infrastructure the moment it touches the edge. That's reassuring, right?
Dive Deep
Each profile carries both strategic and tactical modules:
- Alternative aliases
- Origin tracking
- Historical threat event volume
- MITRE ATT&CK mapping (the adversary's technical methods)
Using it is easy. Click a Threat Actor name in the Threat Events table to open that adversary's profile and check their aliases and attack stats. For a broader view, head to Cloudflare Dashboard > Application Security > Threat Intelligence and open the new Threat Actors tab, where a card-based directory lists all the entities tracked by Cloudforce One.
Want to learn more? Check out the Cloudforce One documentation.
Wrap-up
- Cloudflare's Security Center now has Threat Actor Profiles, letting you jump from a Threat Event straight to the adversary's identity
- Aliases, origin, historical event volume, and MITRE ATT&CK mapping reveal the "Who, Why, and How" of an attacker
- Cloudflare's view of ~20 % of the web means real-time malicious infrastructure data
- It's a great fit for SOC and security folks who need to quickly judge "Can I ignore this alert, or am I actually being targeted?"