Cloudflare WAF Adds Four Managed Threat-Intelligence IP Lists

Cloudflare is expanding the threat-intelligence options available in its Web Application Firewall (WAF) with four new managed IP lists that can be referenced in any custom firewall rule. The lists categorize IP addresses as VPNs, Botnets, Command and Control Servers, Malware, and Anonymizers. They join the Open SOCKS Proxy list introduced in March 2021.

Managed lists are maintained by Cloudflare and built from threat feeds that aggregate observed internet-wide patterns. Enterprise customers can use them in the firewall rule builder or with Advanced Rate Limiting, allowing policies such as blocking all traffic from VPN-classified IPs or rate-limiting Anonymizer traffic. Existing custom IP lists remain available for the same purposes.

Managed IP Lists can be used in WAF rules to manage incoming traffic from these IPs.

Feed Composition and Verification

Each IP category is determined by combining open-source data with behavioral analysis performed across Cloudflare's network. After an IP is added to a feed, Cloudflare verifies its classification before feeding the information back into its security systems and making it available as a managed IP list. The list contents are updated several times per day.

Cloudflare curates multiple data sources selected for reliable coverage and a low false-positive rate, acknowledging that an IP's role can shift over time—a cloud provider address that distributes malware today may be a critical business resource tomorrow. Publicly available OSINT data, such as Tor exit nodes, is integrated directly into the Anonymizer list so customers do not need to manage these feeds across their own infrastructure. Other classifications are vetted using DNS-based techniques including lookup, PTR record lookup, and passive DNS observation from Cloudflare's network.

Malware and command-and-control lists are built from curated partnerships, with preference given to sources that identify security threats lacking associated DNS records. The Anonymizer list is a superset that covers VPNs, open proxies, and Tor nodes; the narrower VPN list covers known commercial VPN nodes, while the Open Proxies list tracks proxies relaying traffic without authentication.

Dashboard Context for WAF Events

Beyond enforcing rules, the new lists also surface contextual information in the dashboard. When a WAF event's source IP matches one of the threat feeds, the category is shown directly on the analytics page. A blocked request probing for known software vulnerabilities, for example, would display context if the source IP is classified as part of a VPN or Botnet.

When the source IP of a WAF event matches one of the threat feeds, we provide contextual information directly onto the Cloudflare dashboard.

This visibility helps identify traffic patterns and informs policy decisions, such as whether to add a rate-limiting rule that constrains how many requests these actors can send within a time window.

Plan Availability and Future Lists

Access depends on the customer's plan: all paying plans can view the contextual dashboard information, while the managed lists themselves are limited to Enterprise zones within an Enterprise account.

FREE PRO BIZ ENT with WAF Essential ENT with WAF Advanced *
Annotations x
Open Proxies x x x
Anonymizers x x x x
VPNs x x x x
Botnets, command and control x x x x
Malware x x x x

Cloudflare is also preparing additional lists for future release, specifically targeting cloud providers and Carrier-grade Network Address Translation (CG-NAT).