· via Cloudflare blog
Cloudflare launches Threat Signals, free agentic threat-intelligence skills for all accounts
Cloudflare's Threat Signals uses agentic skills to summarize open-source threat reports, extract indicators of compromise and turn them into WAF-ready threat events — free for every account.

Cloudflare has launched Threat Signals, a set of agentic AI skills that turn open-source threat research into structured, enforcement-ready intelligence, and it is available to every Cloudflare account at no cost. According to the Cloudflare blog, the company is simultaneously opening its Cloudforce One Threat Events Platform, its core threat-intelligence offering, to all accounts for free.
What Threat Signals does
The service monitors open-source reporting that the customer selects via RSS feeds and processes each new article the way an experienced analyst would: it summarizes the report, surfaces key context, extracts and normalizes indicators of compromise, and applies tags. The result is stored as a contextualized indicator — a Threat Event — inside the account's private threat-intelligence dataset, where it can immediately be used in a WAF policy.
Cloudflare frames the underlying problem as one of unstructured data. Analysts have long automated structured feeds into SIEMs and WAFs, but converting a research write-up into usable indicators has stayed manual: reading, summarizing, reformatting values, tagging against an internal taxonomy, loading results into a threat-intelligence platform and keeping the source link intact. According to the Cloudflare blog, that process does not scale, context gets stripped away along the way, and the end state is familiar — weeks later a domain sits on a blocklist and nobody can explain why it is there.
How the pipeline works
Users add an RSS feed, give it a name and category, and set how often it is polled; RSS 2.0, Atom and RSS 1.0/RDF are all supported. Each feed runs through a workflow that periodically checks for new articles, uses Cloudflare's Markdown quick action to fetch and clean the article text, and stores the result in R2. The text then passes through an indicator-of-compromise extractor and a set of default Cloudforce One-defined skills that produce the summary, apply tags based on the account's configuration, and add context at the indicator level.
Everything is searchable and tagged, and each extracted indicator is backed by a threat event that keeps the event, its indicators, its tags and the original report connected, so an analyst can always trace where a piece of intelligence came from and why it is in the dataset.
Free tier and enterprise extras
On the free tier, every account gets API and dashboard access to Threat Signals with the ability to select one RSS feed, a private dataset built from that feed and stored for up to 30 days, and API and dashboard access to the Threat Events Platform to investigate events, indicators and tags.
Essentials, Advantage and Elite enterprise customers can extend the offering with additional RSS feeds, access to Cloudforce One's proprietary threat-intelligence datasets, the ability to generate custom agentic skills, higher storage for derived reporting, and custom WAF rules built on both open-source and proprietary threat events. Cloudflare says customers reported that their existing platforms stalled at around 100 polled RSS feeds, which motivated building a system with far more headroom.
What Cloudflare says it learned
Threat Signals began as a one-week internal prototype built by a threat analyst, and the company says the hard part was not parsing but making output that analysts would actually trust. Two constraints emerged from customer feedback: tagging is limited to each account's existing tag catalog, because inventing a new vocabulary would force teams to reconcile two taxonomies; and the system records whether each tag was applied automatically or by a human, which reportedly made analysts far more willing to rely on automatic tagging. In early testing, the detail analysts kept returning to was the persistent link between an event and the report it came from.
Why it matters
The launch takes a workflow that previously required scarce analyst time or bespoke engineering and puts a working version of it in every account, including the free tier. It also closes the loop between intelligence and enforcement: an indicator pulled from a research post can become a WAF rule without leaving the platform, with its provenance attached. And it is a concrete example of agentic AI shipped with deliberate guardrails — fixed tag vocabularies and recorded provenance — rather than open-ended generation. Cloudflare says more ingestion pipelines beyond RSS are coming next. Threat Signals is generally available now via the API and the dashboard under Application Security → Threat Intelligence → Threat Signals.
- #cloudflare
- #threat-intelligence
- #security
- #ai-agents
- #waf