Skip to content
INTERNET INFRASTRUCTURE & NETWORKS

Cloudflare Democratizes Threat Intelligence with AI-Driven ‘Threat Signals’ Platform

Organizations around the globe can now scale their threat intelligence expertise with the same ease they scale modern infrastructure, following a major security announcement from Cloudflare. While network defenders and threat intelligence analysts have long automated the ingestion of structured threat feeds to enrich security information and event management (SIEM) systems or web application firewalls (WAFs), handling unstructured reporting has historically demanded intensive manual labor. Transforming a complex research post into actionable indicators that automated tools can actually use—without stripping away the vital context that explains why those threats matter—has remained a persistent bottleneck for security teams.

To solve this challenge, Cloudflare has introduced Threat Signals, a platform designed to make that operational process possible to automate at scale. Launching immediately and made available across every Cloudflare account, Threat Signals leverages advanced AI skills to revolutionize how open-source research is processed. The platform turns open-source reporting chosen by organizations into fully actionable intelligence through agentic skills that summarize reports, surface key context, extract and normalize indicators of compromise (IOCs), and apply precise tags—all inside a private, account-scoped dataset. The ultimate result is a contextualized indicator stored safely within an organization’s private Threat Intelligence dataset as a Threat Event, which can then be instantly applied to enforce robust WAF policies.

Alongside the debut of Threat Signals, Cloudflare is expanding access to its core threat intelligence offering, the Cloudforce One Threat Events Platform, making it available to all Cloudflare accounts at no additional cost. Enterprise customers utilizing Essentials, Advantage, and Elite tiers will be able to extend this baseline offering significantly. These enterprise organizations can tap into an expanded volume of RSS feeds, gain access to Cloudforce One’s proprietary threat intelligence datasets, generate custom agentic skills, utilize higher storage allocations for Threat Signals-derived open-source reporting, and craft custom WAF rules drawing directly from both open-source and proprietary threat events.

Discovery Is Only the Beginning of Effective Defense

Cloudflare initially focused its efforts on open-source intelligence because it represents the most prominent proving ground for the real-world power of agentic workflows. In conversations with security leaders, the company repeatedly heard that legacy platforms struggle to scale beyond polling a modest limit of roughly 100 RSS feeds. Acknowledging the critical impact that open-source reporting plays in helping defenders comprehend the modern threat landscape, Cloudflare set out to engineer an infinitely scalable platform.

Security researchers regularly publish exhaustive, detailed findings regarding emerging vulnerabilities, malicious infrastructure, active phishing campaigns, sophisticated malware families, and persistent threat actors. Although RSS feed readers have long made it easier to discover these new reports, discovery represents merely the initial step. Transforming raw data into a reliable, usable workflow backed by consistent analytical expertise is the definitive key to building active, resilient defenses.

Historically, specialized expertise has been nearly impossible for organizations to replicate at scale. When a detailed report explains the exact mechanics of a threat campaign and maps out the underlying infrastructure, analysts cannot simply push raw numbers into a system. Before an analyst can effectively utilize that information, they must read and comprehend the text, separate transient noise from genuine risk, extract indicators of compromise, normalize those indicators into standard formats, and map the findings back to existing organizational taxonomies.

Repeating this rigorous manual process across dozens of disparate sources consumes precious time. More importantly, almost every step hinges entirely on human judgment, creating a vulnerability where vital context is frequently lost along the way. Indicators inserted into traditional threat intelligence platforms are frequently stripped away from the surrounding context that explains why they matter and how they should be evaluated later in the remediation cycle. It comes as little surprise that weeks later, when an unfamiliar domain is abruptly pushed to a corporate blocklist, internal teams struggle to remember why the decision was made.

How Threat Signals Operates in Practice

Threat Signals relies on standard RSS protocols to monitor the specific open-source reporting that matters most to an enterprise or individual organization. Administrators can easily add an RSS feed, assign it a recognizable name and category, and configure how frequently Threat Signals polls the source for fresh content. The platform natively supports all three major feed specifications, including RSS 2.0, Atom, and RSS 1.0/RDF.

Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account

Each selected feed enters an automated workflow that periodically polls for newly published articles. The system utilizes Browser Run’s Markdown quick action capability to fetch and clean the raw article text, converting it into a readable markdown format that is subsequently stored securely in R2 storage. This cleaned text is then fed directly into an advanced indicator of compromise extractor alongside a set of default, Cloudforce One-defined skills. These skills summarize the content, apply relevant tags based on the account’s unique configuration, and add contextualization directly at the IOC level.

The resulting output provides a concise summary and highlighted key points, enabling analysts to quickly grasp what transpired, who was impacted, and why the report warrants attention. Everything generated by the platform is fully searchable and tagged, allowing security teams to effortlessly locate relevant articles across the entire ecosystem.

Furthermore, every extracted indicator is backed by an explicit threat event residing inside the account’s private Threat Signals dataset. The event itself, along with its associated indicators, tags, and the original report, remain permanently linked. This structural connection ensures analysts can always trace the intelligence back to its origin and understand the reasoning behind its inclusion. These enriched indicators can then be leveraged to create automated WAF rules directly from threat events, safeguarding applications and underlying infrastructure against emerging vectors.

Lessons Learned During Development

Developing Threat Signals required overcoming significant engineering challenges that extended far beyond basic data parsing. While writing a simple script to pull an RSS feed and extract IP addresses using regular expressions is relatively straightforward—the very first version of Threat Signals began as a one-week internal prototype built by a threat analyst seeking better ways to consume the reports she was reading—scaling that capability into a robust, dependable tool for every user account proved far more demanding. The most complex hurdle involved ensuring the generated output was something security analysts would genuinely trust and utilize in production environments.

During development, engineers initially considered allowing the system to dynamically generate whatever tags seemed appropriate for a given piece of content. However, security teams pushed back strongly against this idea, noting that intelligence labeled in an unfamiliar vocabulary becomes much harder to operationalize because teams are forced to reconcile multiple vocabularies simultaneously. In response, Cloudflare restricted AI-driven tagging strictly to each account’s pre-existing tag catalog.

Similarly, recording whether a tag was applied automatically by the system or manually by a human analyst turned out to be an essential piece of metadata. Practical testing revealed that analysts were significantly more willing to trust automated tagging when they maintained clear visibility into exactly which tags were applied by the algorithm.

While summaries are undoubtedly useful and attract immediate user attention, early testing highlighted that analysts repeatedly returned to the persistent link connecting a threat event to its source report. As complex investigations progressed, this direct traceability consistently helped teams keep track of dispersed indicators and maintain a clear understanding of why each piece of data mattered within the broader scope of an incident.

Looking Ahead at Threat Ingestion

Open-source reporting extends far beyond traditional RSS feeds, and modern security analysts require the ability to consume threat intelligence seamlessly across a wide variety of formats and operational pipelines. Having established the foundational building blocks for ingesting indicators from data feeds into its platform, Cloudflare views the incorporation of additional consumers as a natural evolution. The company plans to introduce support for a broader array of data ingestion pipelines, enabling organizations to bring even more actionable intelligence onto a unified platform to protect their networks.

Threat Signals is now generally available for all Cloudflare accounts through both the API and the user dashboard. Users can access the feature by logging into the Cloudflare dashboard, navigating to Application Security, selecting Threat Intelligence, moving to Threat Signals, and adding their preferred RSS feeds.

Leave a Reply

Your email address will not be published. Required fields are marked *