You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/content/docs/security-center/blocked-content.mdx
+5-2Lines changed: 5 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,12 +5,15 @@ sidebar:
5
5
order: 8
6
6
---
7
7
8
+
import { DashButton } from"~/components";
9
+
8
10
If your domain has content that has been blocked, Blocked Content on the dashboard gives you the ability to request the Trust and Safety team to remove a block.
9
11
10
12
To view Blocked Content on the dashboard:
11
13
12
-
1. Log in to your [Cloudflare dashboard](https://dash.cloudflare.com/) and select your account.
13
-
2. Go to **Security Center** > **Blocked Content**.
14
+
1. In the Cloudflare dashboard, go to the **Blocked Content** page.
While the Brand Protection tool is in beta, all Cloudflare Enterprise customers have automatic access to Brand Protection, including five saved queries. Only Admin, Super Admin and users with a Brand Protection role can access Brand Protection
@@ -19,22 +19,22 @@ While the Brand Protection tool is in beta, all Cloudflare Enterprise customers
19
19
20
20
To start searching for new domains that might be trying to impersonate your brand:
21
21
22
-
1.Log in to your [Cloudflare dashboard](https://dash.cloudflare.com/) and select your account.
22
+
1.In the Cloudflare dashboard, go to the **Brand Protection** page.
23
23
24
-
2. Go to **Security Center** > **Brand Protection**.
3. In **String query**, provide a name for your query. You can add multiple brand phrases on the same query, and the results will generate matches for all of those. Once you entered the string queries, select **Search matches**.
26
+
2. In **String query**, provide a name for your query. You can add multiple brand phrases on the same query, and the results will generate matches for all of those. Once you entered the string queries, select **Search matches**.
27
27
28
-
4. In the **Character distance**, select from `0-3`. The number of characters the results can differ from your domain.
28
+
3. In the **Character distance**, select from `0-3`. The number of characters the results can differ from your domain.
29
29
30
30
:::note
31
31
32
32
If a brand phrase or search term has less than five characters, you can only choose a max distance of `0` (zero).
33
33
:::
34
34
35
-
5. You can select **Save query** to monitor it in the future and perform other actions, such as delete, clone and set up alerts, according to your Paid plan limits.
35
+
4. You can select **Save query** to monitor it in the future and perform other actions, such as delete, clone and set up alerts, according to your Paid plan limits.
36
36
37
-
6. To export all matches from a saved query, select your **Query name** > select the three dots > **Export matches**.
37
+
5. To export all matches from a saved query, select your **Query name** > select the three dots > **Export matches**.
38
38
39
39
In the section **Monitor Strings**, you can check all the string queries that you selected to monitor. You can delete, clone, or create notifications for a string query. Refer to [Brand Protection Alerts](#brand-protection-alerts) to set up notifications.
40
40
@@ -46,20 +46,20 @@ You can only submit an abuse report if your domain is with [Cloudflare Registrar
46
46
47
47
To submit abuse reports directly from the dashboard:
48
48
49
-
1. Go to the **Query name** you want to report.
50
-
2. Select **Report to Cloudflare**.
51
-
3. Fill in the details to submit an abuse report.
52
-
4. Select **Submit**.
49
+
1. Go to **Monitor Strings**, select the query you want to report.
50
+
3. Select **Report to Cloudflare**.
51
+
4. Fill in the details to submit an abuse report.
52
+
5. Select **Submit**.
53
53
54
54
## Logo queries
55
55
56
56
To set up a new logo query:
57
57
58
-
1.Go to **Security Center** >**Monitor Logos** and select **Add logo**.
59
-
2. Add a name for your query and upload your logo. Only the `.png`, `.jpeg`, and `.jpg` file extensions are supported.
60
-
3. Select **Save logo**.
58
+
1.Select**Monitor Logos** and select **Add logo**.
59
+
3. Add a name for your query and upload your logo. Only the `.png`, `.jpeg`, and `.jpg` file extensions are supported.
60
+
4. Select **Save logo**.
61
61
62
-
The browser will return to the **Monitor Images** overview page, where you can access your query and configure notifications.
62
+
The browser will return to the **Monitored Logos** page, where you can access your query and configure notifications.
You can also use Cloudforce One via [REST API](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/assets/).
23
24
@@ -31,25 +32,28 @@ Cloudforce One Threat Intelligence displays the following information:
31
32
## Submit RFIs
32
33
33
34
To submit RFIs (Request for Information):
34
-
35
-
1. Log in to the [Cloudflare dashboard](https://dash.cloudflare.com/) and select your account.
36
-
2. Go to **Security Center** > **Threat Intelligence** > **Requests for Information**.
35
+
36
+
1. In the Cloudflare dashboard, go to the **Threat Intelligence** page.
4. Fill in the required fields, then select **Save**.
39
43
40
44
<Detailsheader="List of RFI types">
41
45
42
46
The Cloudflare dashboard presents the following request types when you want to configure a Cloudforce One Requests for Information:
43
47
44
-
-**Binary Analysis - IOCs**: Conduct high level malware analysis to produce [indicators](https://www.cloudflare.com/en-gb/learning/security/what-are-indicators-of-compromise/) such as a call-back domain or IP address.
48
+
-**Binary Analysis - IOCs**: Conduct high level malware analysis to produce [indicators](https://www.cloudflare.com/en-gb/learning/security/what-are-indicators-of-compromise/) such as a call-back domain or IP address.
45
49
46
50
-**Binary Analysis - Report**: A thorough analysis of a malware sample to produce an attribution assessment and extract the configuration of the sample for further analysis. Useful for customers that are investigating a problem or trying to develop detection logic in an [EDR](https://en.wikipedia.org/wiki/Endpoint_detection_and_response) or network sensor.
47
51
48
-
-**DDoS Attack**: Confirm if an attack is happening against a specific website to share any available indicators and potential attribution.
52
+
-**DDoS Attack**: Confirm if an attack is happening against a specific website to share any available indicators and potential attribution.
49
53
50
54
-**Indicator Analysis - IOCs**: Conduct DNS lookups, origin pivots, and account pivots to provide indicators such as DNS resolutions, origin IPs, and subdomains. Analysis can include account registration patterns and victimology.
51
55
52
-
-**Indicator Analysis - Report**: A thorough analysis of indicators written in a formal, structured format. In addition to listing [Indicator of compromise (IOCs)](https://www.cloudflare.com/en-gb/learning/security/what-are-indicators-of-compromise/), the report explains how IOCs function within the attack chain, and adds context by linking IOCs to specific campaigns and/or threat actors and their TTPs.
56
+
-**Indicator Analysis - Report**: A thorough analysis of indicators written in a formal, structured format. In addition to listing [Indicator of compromise (IOCs)](https://www.cloudflare.com/en-gb/learning/security/what-are-indicators-of-compromise/), the report explains how IOCs function within the attack chain, and adds context by linking IOCs to specific campaigns and/or threat actors and their TTPs.
53
57
54
58
-**Passive DNS Resolution**: Research the pair of an IP address to the domain it resolved to during a specified period of time.
55
59
@@ -82,9 +86,9 @@ To delete your RFI, the status must be `Open`. Go to the RFI you want to delete,
82
86
83
87
### Upload and download attachment
84
88
85
-
You can also choose to upload and download an attachment.
89
+
You can also choose to upload and download an attachment.
86
90
87
-
Under **Attachments**, select the file you want to upload, then select **Save**.
91
+
Under **Attachments**, select the file you want to upload, then select **Save**.
88
92
89
93
To download an attachment, select **Download** on the attachment.
90
94
@@ -94,8 +98,9 @@ Threat events allow you to protect your assets and respond to emerging threats.
94
98
95
99
To access and analyze threat intelligence data on the dashboard:
96
100
97
-
1. Log in to the [Cloudflare dashboard](https://dash.cloudflare.com/) and select your account.
2. Go to **Threat Events** > **Analyze with Cloudy**.
135
142
136
143
Cloudy will show you the top threat events, analyze them, and give you a summary of threat events. You can also decide to receive an analysis based on **Attacker**, **Indicator**, and more. For example, you can enter "Give me a summary of threat events for ABC Attacker". Cloudy will then summarize threat events for ABC attacker.
Copy file name to clipboardExpand all lines: src/content/docs/security-center/investigate/change-categorization.mdx
+11-9Lines changed: 11 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,6 +6,8 @@ sidebar:
6
6
7
7
---
8
8
9
+
import { DashButton } from"~/components";
10
+
9
11
Cloudflare sorts domains into categories based on their content and security type. You can request categorization changes via the [dashboard](#via-the-cloudflare-dashboard), [Cloudflare Radar](#via-cloudflare-radar), or the [API](#via-the-api).
10
12
11
13
For a detailed list of categories, refer to [Domain categories](/cloudflare-one/policies/gateway/domain-categories/).
@@ -14,32 +16,32 @@ For a detailed list of categories, refer to [Domain categories](/cloudflare-one/
14
16
15
17
To request a categorization change via the Cloudflare dashboard:
16
18
17
-
1.Log in to the [Cloudflare dashboard](https://dash.cloudflare.com/) and select your account.
19
+
1.In the Cloudflare dashboard, go to the **Investigate** page.
4. In **Domain overview**, select **Request to change categorization**.
25
+
3. In **Domain overview**, select **Request to change categorization**.
24
26
25
-
5. Choose whether to change a [security category](/cloudflare-one/policies/gateway/domain-categories/#security-categories) or a [content category](/cloudflare-one/policies/gateway/domain-categories/#content-categories).
27
+
4. Choose whether to change a [security category](/cloudflare-one/policies/gateway/domain-categories/#security-categories) or a [content category](/cloudflare-one/policies/gateway/domain-categories/#content-categories).
26
28
27
-
6. Choose which categories you want to add or remove from the domain.
29
+
5. Choose which categories you want to add or remove from the domain.
28
30
29
31
:::note[Content category limit]
30
32
31
-
A domain cannot have more than two associated content categories. To propose changes to categories of a domain with more than two existing categories, remove one or more of the existing categories.
33
+
A domain cannot have more than two associated content categories. To propose changes to categories of a domain with more than two existing categories, remove one or more of the existing categories.
32
34
:::
33
35
34
-
7. Select **Submit** to submit your request for review.
36
+
6. Select **Submit** to submit your request for review.
35
37
36
38
Requesting a security category change will trigger a deeper investigation by Cloudflare to confirm that the submission is valid. Requesting a content category change also requires Cloudflare validation, but the turnaround time for these submissions is usually shorter as it requires less investigation.
37
39
38
40
Your category change requests will be revised by the Cloudflare team depending on the type of change. If your requests have been reviewed and applied by the Cloudflare team, the new categories will be visible in the Cloudflare dashboard in **Security Center** > **Investigate**, as well as in [Cloudflare Radar](https://radar.cloudflare.com/).
39
41
40
42
:::caution
41
43
42
-
Cloudflare does not guarantee the category change will be approved.
44
+
Cloudflare does not guarantee the category change will be approved.
Copy file name to clipboardExpand all lines: src/content/docs/security-center/investigate/investigate-threats.mdx
+17-8Lines changed: 17 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ sidebar:
6
6
7
7
---
8
8
9
-
import { Render } from"~/components"
9
+
import { Render, DashButton } from"~/components"
10
10
11
11
Users can investigate the details of an IP address, domain name, URL, or Autonomous System Number (ASN). You can find the Investigate feature in your Cloudflare account's Security Center and in [Cloudflare Radar](https://radar.cloudflare.com/scan).
12
12
@@ -55,8 +55,11 @@ When you search for a hash, the Cloudflare dashboard will provide a URL report f
55
55
56
56
To search using a hash:
57
57
58
-
1. Log in to your [Cloudflare dashboard](https://dash.cloudflare.com/) and select your account.
59
-
2. Go to **Security Center** > **Investigate**. Enter the hash, then select **Search**.
58
+
1. In the Cloudflare dashboard, go to the **Investigate** page.
0 commit comments