From unstructured reporting to actionable indicators
Security teams have long automated ingestion of structured threat feeds to enrich a SIEM or WAF. The harder problem is unstructured reporting, where an analyst must turn a research post into usable indicators without discarding the context that explains their significance. Threat Signals, launching today and available to every Cloudflare account, applies agentic skills to that problem.
The platform takes open-source reporting you select and runs it through skills that summarize reports, surface key context, extract and normalize indicators of compromise, and apply tags inside a private, account-scoped dataset. Each contextualized indicator becomes a Threat Event in the account's private Threat Intelligence dataset, ready to be applied in a WAF policy.
Cloudforce One's Threat Events Platform is also expanding to all Cloudflare accounts for free. Each account receives:
- API and dashboard access to Threat Signals with the ability to select one RSS feed
- A private dataset built from that RSS feed, tailored to your reporting requirements and stored for up to 30 days
- API and dashboard access to Threat Events Platform to investigate events, indicators, and tags related to the private dataset
Essentials, Advantage, and Elite enterprise customers can extend the offering with additional RSS feeds, access to Cloudforce One's proprietary threat intelligence datasets, custom agentic skills, higher storage options for derived open-source reporting, and custom WAF rules on open-source and proprietary threat events.

How the pipeline works
Threat Signals monitors open-source reporting over RSS. You add a feed, assign it a recognizable name and category, and configure how often Threat Signals checks for new content. RSS 2.0, Atom, and RSS 1.0/RDF are all supported.
Each selected feed enters a Workflow that periodically polls for new articles. It uses Browser Run's Markdown quick action to fetch and clean article text into readable markdown, which is stored in R2. The text then passes into an indicator of compromise extractor and a set of default Cloudforce One-defined skills that summarize the content, apply tags based on account configuration, and add IOC-level contextualization.
The result is a concise summary and key points an analyst can scan to understand what happened, who was affected, and why the report matters — all searchable and tagged. Every extracted indicator is backed by a threat event in the account's private Threat Signals dataset, keeping the event, its indicators and tags, and the original report connected so provenance is always traceable. Indicators can then be used to create WAF rules from threat events.

Design decisions behind the output
Parsing was never the difficult part. Threat Signals began as a one-week internal prototype built by a threat analyst; making it dependable for every account meant making the output something analysts would trust and use.
Tagging was the first constraint. Allowing the system to invent its own vocabulary would force teams to reconcile two taxonomies, so AI tagging is limited to each account's existing tag catalog. Recording whether a tag was applied automatically or by an analyst also proved essential: analysts were far more willing to trust automatic tagging when they could see exactly which tags it applied.
Summaries are useful and are what users notice first, but in early testing analysts consistently returned to the link between an event and the report it came from. That link helped them track indicators through an investigation and understand why each one mattered.
Availability and next steps
Threat Signals is generally available for every Cloudflare account via API and the dashboard. Navigate to Application Security → Threat Intelligence → Threat Signals and add your RSS feed; the documentation is here. Cloudforce One's threat intelligence research is also available, and enterprise teams can talk to their account team about putting Threat Events to work.
Open-source reporting extends beyond RSS, and analysts need to consume intelligence across a range of formats and pipelines. With the building blocks for ingesting indicators from data feeds in place, the next step is adding more consumers through additional supported data ingestion pipelines.



