Skip to content

SYSTEM Cited by 2 sources

Cloudforce One

Overview

Cloudforce One is Cloudflare's threat intelligence, research, and operations team — sits within the Cloudflare security organisation. It turns what Cloudflare sees across its network (~20% of global web traffic) into actionable intelligence: tracked adversaries, emerging campaigns, and indicators of compromise (IOCs).

Architectural role

The key contribution is closing the gap between knowing a threat exists and blocking it in production. Traditional threat-intel lifecycle:

threat report → feed → company ingests feed → deploys defence

Cloudforce One shortens this: intelligence is generated from the same network that enforces defences. Cloudflare customers can now use Cloudforce One threat intelligence directly within the WAF to block high-risk traffic — no intermediate feed-ingestion step.

Network-scale advantage

Cloudflare's visibility (~1/5 of web traffic) means the team sees payload mutations, pattern upticks, and attacker-tooling shifts in real time — before they appear in public feeds or advisory databases.

(Source: sources/2026-06-09-cloudflare-defend-against-frontier-cyber-models)

Real-time threat intelligence detection (2026-09-29 framework)

In June 2026 Cloudflare launched always-on detection based on Cloudforce One's threat-intelligence feeds — Cloudforce One customers could deploy protections to block requests originating from compromised infrastructure (the fourth layer of the WAF runtime stack). The 2026-09-29 application-security-framework post announces that Cloudflare is expanding access to Cloudforce One's Threat Events Platform — its core threat-intelligence offering — to all Cloudflare accounts for free. This turns network-scale intelligence into a stage-4 (real-time threat intelligence) input available to every customer, not just the paid Cloudforce One tier, and supplies the threat-intel context the autonomous SecOps platform's specialist agents draw on.

Seen in

Last updated · 766 distilled / 2,225 read