Cloud Shield / Threat investigation
Follow a request from overview to decision.
A traffic spike or blocked request is the start of an investigation. Cloud Shield connects analytics, event filters and IP context so you can understand the activity behind a protection decision and decide what to change.
Capabilities
Threat investigation in practice.
Traffic analytics
Review request volume and protection activity for an application before narrowing the investigation to specific events.
IP investigation
Use IP Spotlight, reputation information and network organization reference data to add context to client activity.
Reusable filters
Save useful filter templates so your team can return to the same investigation criteria when reviewing traffic.
Configuration & visibility
Use the right level of context.
Core traffic visibility and optional intelligence work together, with plan eligibility made explicit.
- Security events
- Inspect the request context and protection decisions behind the activity you see in analytics.
- IP reputation
- Basic includes basic IP reputation. Advanced and Business include the IP Reputation capability.
- Security Insights
- Extend investigations with Security Insights through the separately priced Business Threat Intelligence add-on.
- SIEM Integration
- Discuss the Business SIEM Integration add-on when you need to connect security operations with your wider monitoring workflow.
How it works
Turn an observation into a targeted change.
- 01
Start with the application
Open analytics for the protected domain and locate the time period or activity you want to understand.
- 02
Narrow the investigation
Filter security events, inspect a client IP and review the available reputation and network context.
- 03
Refine protection
Apply a targeted policy or rule change where appropriate, then review the effect on subsequent traffic.
Traffic analytics are available across plans. Threat Intelligence is an optional Business add-on. Compare plans
Frequently asked questions
No. Threat Intelligence and Security Insights require the separately priced Business Threat Intelligence add-on. Core traffic analytics are available across plans.
Basic includes basic IP reputation. Advanced and Business include IP Reputation, as shown in the plan comparison.
Filter templates let you save useful criteria and return to them when reviewing security traffic.
Explore Cloud Shield