Cloudflare Launches Cloudforce One, a Threat Operations and Research Team

Cloudflare today announced the formation of Cloudforce One, a new threat operations and research team. While the team will produce research, its stated primary mission is to track and disrupt threat actors rather than simply publish reports.

According to Blake Darché, the team's leader and Area 1's co-founder and former head of Threat Intelligence, the move responds to a common complaint from security teams: they receive plenty of threat intel from vendors that does little to improve their actual security posture. Customers want deeper insight into the techniques and actors targeting their industries, but more importantly, they want protection with minimal involvement. Cloudforce One is built around that objective.

Darché's background includes a founding role in CrowdStrike's services organization and prior work as a Computer Network Exploitation Analyst at the National Security Agency (NSA). Cloudflare acquired Area 1 earlier this year. The new team is structured into three groups: Threat Research, Malware and Vulnerability Research, and Threat Operations, the latter focused on disrupting identified actors. Team members have previously tracked sophisticated cyber criminals while at the NSA and Area 1, collaborated with governments on disruption efforts, and published "finished intel" reports on topics such as attacks on governments, technology companies, the energy sector, and law firms.

The team is currently hiring.

How Protection and Briefings Will Work

Cloudforce One will work closely with Cloudflare's product, engineering, and security teams to improve protections for all customers, using tactics, techniques, and procedures (TTPs) observed in active campaigns. Customers will see these improvements without needing to take any action. A subset of the team's research will be published on the Cloudflare blog and within the Cloudflare Security Center.

For enterprise customers that want more direct engagement, a new Threat Intelligence subscription will offer one-on-one live briefings, periodic follow-up inquiries, and early access to threat research. Those who do not subscribe will be invited to periodic group briefings.

The dedicated threat intel engineering team paired with Cloudforce One will also introduce new Security Center capabilities, including access to historical threat data via API and threat pivoting features.

Getting Started

Because Cloudforce One's work will automatically improve protection for all Cloudflare customers, there is no required action for those who only want the benefits. Customers interested in industry-specific briefings can contact their Customer Success manager or fill out a form on Cloudflare's website. Those interested in joining Cloudforce One can apply through Cloudflare's open job postings.