Skip to content

SYSTEM Cited by 1 source

Cloudflare Managed Defense

Managed Defense is Cloudflare's managed detection-and-response (MDR) / security-operations team (cloudflare.com/managed-defense). In the 2026-09-29 application-security-framework post it is named as the team co-developing Cloudflare's autonomous security-operations platform — its analysts "are helping us test how evidence is collected, correlated, and turned into recommendations."

Role in the "investigate, respond, and learn" stage

The framework's Stage 4 argues that security operations must identify sequences of behavior that lead to compromise, not evaluate alerts in isolation — because a breach (the July 2026 OpenAI / Hugging Face incident) is a timeline of related events (unauthorized message board in May, internal network scanning in June, movement across environments in July) that each look partial on their own. Human SOC teams protecting large attack surfaces with limited resources cannot manually stitch alerts from many tools and datasets into a campaign fast enough.

Cloudflare is building a platform to automate security operations using a three-stage specialized-agent decomposition, and Managed Defense is the human SOC team validating it:

  1. Deterministic workflows establish customer + investigation context from trigger history, traffic baselines, enforcement outcomes, and network observations.
  2. A detection agent searches authorized datasets for anomalies and correlations.
  3. Specialist agents review the evidence alongside customer history + threat intelligence, helping analysts connect isolated events to broader campaigns.
  4. The system recommends mitigations (rate limiting, WAF, DDoS protection changes) — for human approval (a human-in-the-loop gate, not autonomous enforcement).

Managed Defense's analysts test each of these steps before the capabilities are made "available more broadly over time."

The correlation advantage it operates on

Managed Defense sits on top of Cloudflare's combined reverse-proxy + forward-proxy visibility: Application Security signals reveal attempts to exploit a public-facing application, while Cloudflare One surfaces subsequent activity across corporate traffic. Connecting these datasets links an external attack with unusual internal access, internal scanning, or lateral movement — the raw material the detection + specialist agents turn into a timeline of compromise.

Seen in

Last updated · 766 distilled / 2,225 read