Cloudflare WAF Adds Four Managed Threat-Intelligence IP Lists
Cloudflare is expanding the threat-intelligence options available in its Web Application Firewall (WAF) with four new managed IP lists that can be referenced in any custom firewall rule. The lists categorize IP addresses as VPNs, Botnets, Command and Control Servers, Malware, and Anonymizers. They join the Open SOCKS Proxy list introduced in March 2021.
Managed lists are maintained by Cloudflare and built from threat feeds that aggregate observed internet-wide patterns. Enterprise customers can use them in the firewall rule builder or with Advanced Rate Limiting, allowing policies such as blocking all traffic from VPN-classified IPs or rate-limiting Anonymizer traffic. Existing custom IP lists remain available for the same purposes.

Feed Composition and Verification
Each IP category is determined by combining open-source data with behavioral analysis performed across Cloudflare's network. After an IP is added to a feed, Cloudflare verifies its classification before feeding the information back into its security systems and making it available as a managed IP list. The list contents are updated several times per day.
Cloudflare curates multiple data sources selected for reliable coverage and a low false-positive rate, acknowledging that an IP's role can shift over time—a cloud provider address that distributes malware today may be a critical business resource tomorrow. Publicly available OSINT data, such as Tor exit nodes, is integrated directly into the Anonymizer list so customers do not need to manage these feeds across their own infrastructure. Other classifications are vetted using DNS-based techniques including lookup, PTR record lookup, and passive DNS observation from Cloudflare's network.
Malware and command-and-control lists are built from curated partnerships, with preference given to sources that identify security threats lacking associated DNS records. The Anonymizer list is a superset that covers VPNs, open proxies, and Tor nodes; the narrower VPN list covers known commercial VPN nodes, while the Open Proxies list tracks proxies relaying traffic without authentication.
Dashboard Context for WAF Events
Beyond enforcing rules, the new lists also surface contextual information in the dashboard. When a WAF event's source IP matches one of the threat feeds, the category is shown directly on the analytics page. A blocked request probing for known software vulnerabilities, for example, would display context if the source IP is classified as part of a VPN or Botnet.

This visibility helps identify traffic patterns and informs policy decisions, such as whether to add a rate-limiting rule that constrains how many requests these actors can send within a time window.
Plan Availability and Future Lists
Access depends on the customer's plan: all paying plans can view the contextual dashboard information, while the managed lists themselves are limited to Enterprise zones within an Enterprise account.
| FREE | PRO | BIZ | ENT with WAF Essential | ENT with WAF Advanced * | |
|---|---|---|---|---|---|
| Annotations | x | ✅ | ✅ | ✅ | ✅ |
| Open Proxies | x | x | x | ✅ | ✅ |
| Anonymizers | x | x | x | x | ✅ |
| VPNs | x | x | x | x | ✅ |
| Botnets, command and control | x | x | x | x | ✅ |
| Malware | x | x | x | x | ✅ |
Cloudflare is also preparing additional lists for future release, specifically targeting cloud providers and Carrier-grade Network Address Translation (CG-NAT).



