By providing contextual information about cyber threats instead of isolated indicators, Cloudflare’s Cloudforce One threat events platform represents a significant advancement in operational threat intelligence, enabling security teams to respond more effectively to emerging threats. The platform maps threat events to the MITRE ATT&CK framework and cyber kill chain stages, providing security teams with standardized contextual information about attack methodologies. The platform provides security practitioners with actionable insights by analyzing indicators of compromise (IoCs), including IP addresses, ASNs, domains, URLs, and file hashes, with critical contextual information about why these indicators represent potential threats. The platform incorporated this intelligence, allowing analysts to filter events by the “BlackBasta” attacker attribute to discover verified IP addresses, domains, and file hashes associated with this threat actor, as shown below. Cloudflare built the threat events platform using its own Developer Platform, implementing Cloudflare Workers with SQLite-backed Durable Objects for data storage. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 19 Mar 2025 13:35:23 +0000