Threat investigation

Move from traffic analytics to security events, client IP activity and reputation to understand protection decisions and refine your policies.

Cloud Shield / Threat investigation

Follow a request from overview to decision.

A traffic spike or blocked request is the start of an investigation. Cloud Shield connects analytics, event filters and IP context so you can understand the activity behind a protection decision and decide what to change.

Capabilities

Threat investigation in practice.

Traffic analytics

Review request volume and protection activity for an application before narrowing the investigation to specific events.

IP investigation

Use IP Spotlight, reputation information and network organization reference data to add context to client activity.

Reusable filters

Save useful filter templates so your team can return to the same investigation criteria when reviewing traffic.

Configuration & visibility

Use the right level of context.

Core traffic visibility and optional intelligence work together, with plan eligibility made explicit.

Security events
Inspect the request context and protection decisions behind the activity you see in analytics.
IP reputation
Basic includes basic IP reputation. Advanced and Business include the IP Reputation capability.
Security Insights
Extend investigations with Security Insights through the separately priced Business Threat Intelligence add-on.
SIEM Integration
Discuss the Business SIEM Integration add-on when you need to connect security operations with your wider monitoring workflow.

How it works

Turn an observation into a targeted change.

  1. 01

    Start with the application

    Open analytics for the protected domain and locate the time period or activity you want to understand.

  2. 02

    Narrow the investigation

    Filter security events, inspect a client IP and review the available reputation and network context.

  3. 03

    Refine protection

    Apply a targeted policy or rule change where appropriate, then review the effect on subsequent traffic.

Traffic analytics are available across plans. Threat Intelligence is an optional Business add-on. Compare plans

Frequently asked questions

No. Threat Intelligence and Security Insights require the separately priced Business Threat Intelligence add-on. Core traffic analytics are available across plans.

Basic includes basic IP reputation. Advanced and Business include IP Reputation, as shown in the plan comparison.

Filter templates let you save useful criteria and return to them when reviewing security traffic.

Aptranet Cloud Shield

Build protection around your application.

Connect your CDN distribution and choose the policies, rules and optional capabilities your team needs.