Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare’s real-time threat-intelligence service is Cloudforce One Threat Events, a platform that turns attacks observed across Cloudflare’s network into contextual event records—not just lists of suspicious IP addresses. Cloudforce One customers can explore events in the Cloudflare Dashboard or access them through an API, then filter and use the intelligence in their security workflows.

What Cloudforce One Threat Events includes

Cloudflare announced the platform on March 18, 2025. Its events combine indicators of compromise (IoCs) with summaries, associated threat actors, and mappings to MITRE ATT&CK and stages of the cyberattack kill chain. That added context can help security teams assess what an indicator relates to and where activity fits in an attack, rather than treating each indicator as an isolated blocklist entry. Cloudflare’s launch announcement and platform overview describe the service.

Initial event coverage

At launch, Cloudflare said the platform focused on denial-of-service activity and advanced threat operations tracked by Cloudforce One analysts. The company said it planned to expand coverage later to datasets from its Web Application Firewall (WAF), Zero Trust Gateway, and Email Security products. Those were described as planned expansion areas, not as part of the initial coverage.

Network scale behind the events

Cloudflare said it processed 71 million HTTP requests per second and 44 million DNS queries per second, and blocked an average of 227 billion cyber threats per day during Q4 2024. These are Cloudflare-reported network figures; the blocked-threat average refers specifically to that quarter. The scale helps explain the telemetry available to the platform, but it does not by itself establish the accuracy, completeness, or detection rate of any individual event.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
GL.iNet GL-MT2500A Brume 2 Wired VPN Security Gateway 2.5G WAN
  • 【Compatible with 30+ VPN service providers】Pre-installed with OpenVPN and WireGuard. OpenVPN speeds up to 150 Mbps; WireGuard speeds up to 355 Mbps. ***NO Wi-Fi function***
  • 【Full Protection for Your Network】 Cloudflare encryption supported to protect the privacy. IPv6 security protocol supported. (To enable IPv6 function, please access to Admin Panel -> NETWORK -> IPv6.)
  • 【Support VPN Cascading】Allow VPN server and VPN client operate simultaneously within the same device, enabling user to access local network servers with accessing public internet as a VPN client in the meantime.
  • 【Ideal Gateway for Hosting a VPN Server at Home or Office】Access sensitive information stored under a corporate private network or access local files and bypass geo-blocking securely while working remotely.
  • 【Advanced Hardware Specification】Equipped with 2.5 gigabit WAN port, 1 gigabit LAN port with USB 3.0 port, as well as 8 GByte EMMC (embedded multimedia card) storage for offline data storage.

How teams investigate and use events

The platform is designed to let customers investigate patterns in observed activity as well as retrieve indicators. Cloudflare describes filters for questions such as which threat actors are targeting a particular industry or country, which indicators may help block an attack, and what an adversary did across the kill chain.

Dashboard investigation

In the Cloudflare Dashboard, Cloudforce One customers use the Security Center to view Threat Events. The interface includes an Attacker Timelapse view and a filterable events table, giving analysts ways to examine activity over time and narrow events by relevant attributes.

API and automation

Cloudforce One customers can also use the Threat Events API to bring intelligence into security workflows. That makes the service usable for automation and integration, though the cited product materials do not establish specific third-party SIEM integrations, API limits, or a universal setup procedure.

Alerts for saved views

On April 8, 2026, Cloudflare added alerts associated with saved views. Customers can configure immediate alerts or daily digests through the Notifications Center. This update makes saved filters useful not only for investigations but also for monitoring selected activity over time. Cloudflare’s announcement of Threat Events alerts describes the addition.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What powers the platform—and what the claims establish

Cloudflare says Threat Events uses Workers and SQLite-backed Durable Objects to store customizable datasets and scale across its network. This describes the company’s stated architecture; it does not disclose enough implementation detail to independently assess data retention, event latency, or how customers’ customizations are isolated.

Cloudflare also reports that a Fortune 20 threat-intelligence team tested the platform against 110 other sources and ranked it first, describing it as “very much a unicorn.” The company’s account does not name the evaluator or provide the methodology or independent corroboration, so this should be read as a vendor-reported evaluation rather than a general comparative benchmark.

Cloudflare’s launch materials frame the service as a response to threat feeds that can be stale or fragmented. The platform’s event context, network-derived observations, filtering, and API are relevant to that goal, but buyers should still evaluate freshness, coverage, and fit for their own environment rather than infer performance from the network-scale figures alone.

Who can access Cloudforce One Threat Events?

Cloudflare identifies the service as available to Cloudforce One customers through the Cloudflare Dashboard and Threat Events API. The cited materials do not state public pricing, eligibility details beyond customer access, or whether the service is available as a standalone purchase. Organizations considering it should confirm current access and commercial terms with Cloudflare.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.