事件表格是安全中心中的一个详细视图,用户可以根据多种条件筛选以深入查看特定的威胁活动。在此,用户可以使用 Cloudflare 的流量洞察探索特定的威胁事件和攻击活动。最为关键的是,这个表格将为用户提供可操作的入侵指标和事件摘要,使其能够有效防御自己的服务。事件表格中的所有数据同时可通过 Cloudforce One 威胁事件 API 访问。
为了展示威胁事件的强大力量,我们来探索一个真实世界的案例:
最近泄露的 Black Basta 犯罪集团聊天记录披露了关于其受害者、作案手法和基础设施采购的详细信息。尽管我们无法确认这些泄露的聊天记录是否经过任何篡改,但聊天中提及的基础设施很容易验证。因此,这些威胁情报现在作为威胁事件平台中的事件提供,并附加额外的独特 Cloudflare 上下文信息。
分析人员在搜寻 Black Basta 使用的域名、主机和文件样本时,可以利用威胁事件平台获得有关该威胁行为者活动的宝贵洞察。例如,在威胁事件用户界面中,用户可以通过在下拉菜单中选择“BlackBasta”来过滤“攻击者”列,如下图所示。这将提供一份经过验证的 IP 地址、域名和文件哈希值的列表以供进一步调查。若要进一步了解 Cloudflare 有关 Black Basta 威胁活动的独特洞察,请参阅《Black Basta 的失误:利用该犯罪集团的泄露聊天记录》。
目前,Cloudforce One 客户已经可以访问我们的 API 和仪表板,从而实现威胁情报与现有系统的无缝集成。此外,客户将很快获得更多威胁事件的可视化和分析工具,以便更好地理解和报告调查发现。即将推出的用户界面将包含攻击者时间线、攻击活动概览和攻击图表的增强可视化,为组织面临的威胁提供更深入的洞察。此外,我们将增加与现有 SIEM 平台集成和跨系统共享指标的功能。
"],"published_at":[0,"2025-03-18T13:10+00:00"],"updated_at":[0,"2025-04-07T23:11:00.151Z"],"feature_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2KDcMhcKUEFoFYIG1taRTs/e2ac7ad2205eda9d9fff64738816b32f/image3.png"],"tags":[1,[[0,{"id":[0,"3DmitkNK6euuD5BlhuvOLW"],"name":[0,"Security Week"],"slug":[0,"security-week"]}],[0,{"id":[0,"6Mp7ouACN2rT3YjL1xaXJx"],"name":[0,"安全"],"slug":[0,"security"]}],[0,{"id":[0,"6hv2Z69PGr0qU411KfQNUE"],"name":[0,"威胁情报"],"slug":[0,"threat-intelligence"]}],[0,{"id":[0,"3GUtnWmux4qZOUh5OjIljE"],"name":[0,"Cloudforce One"],"slug":[0,"cloudforce-one"]}],[0,{"id":[0,"HkD3go6gAP2HK3M4NzrLz"],"name":[0,"Intel"],"slug":[0,"intel"]}],[0,{"id":[0,"1PvAU8aG8p8SvdOGMPtDnO"],"name":[0,"威胁"],"slug":[0,"threats"]}],[0,{"id":[0,"4geXkm5R255jIxA8W3E1bP"],"name":[0,"背景"],"slug":[0,"context"]}]]],"relatedTags":[0],"authors":[1,[[0,{"name":[0,"Alexandra Moraru"],"slug":[0,"alexandra"],"bio":[0,null],"profile_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/URwbDrA0k9GNtNsCsAC7N/930223a35d0c7a39cb843e44f530ccba/alexandra.png"],"location":[0,"London"],"website":[0,null],"twitter":[0,"@alexandramoraru"],"facebook":[0,null]}],[0,{"name":[0,"Blake Darché"],"slug":[0,"blake"],"bio":[0,"Head of Threat Intelligence @ Cloudflare. Former CSO/Co-Founder @ Area 1 Security. Former Incident Response @ CrowdStrike. Former Analyst @ National Security Agency."],"profile_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4bZNxcx9X9SxXvCtiKTmoX/b155cbc0977be2f3ba5a443f19fb692a/blake.jpeg"],"location":[0,null],"website":[0,null],"twitter":[0,"@blakedarche"],"facebook":[0,null]}],[0,{"name":[0,"Emilia Yoffie"],"slug":[0,"emilia-yoffie"],"bio":[0],"profile_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6nc5p2ESsweibmVZ4PzKiM/964fd97363e7365df76c497baee3ee40/Emilia_Yoffie.jpg"],"location":[0],"website":[0],"twitter":[0],"facebook":[0]}]]],"meta_description":[0,"通过我们全新的威胁事件平台,实时洞察不断变化的网络威胁形势。此工具为您的网络安全防御提供切实可行的情报,让您领先于攻击并保护您的关键资产。"],"primary_author":[0,{}],"localeList":[0,{"name":[0,"Blog LL - Unleashing improved context for threat actor activity with our Cloudforce One threat events platform"],"enUS":[0,"English for Locale"],"zhCN":[0,"Translated for Locale"],"zhHansCN":[0,"No Page for Locale"],"zhTW":[0,"Translated for Locale"],"frFR":[0,"Translated for Locale"],"deDE":[0,"Translated for Locale"],"itIT":[0,"English for Locale"],"jaJP":[0,"Translated for Locale"],"koKR":[0,"Translated for Locale"],"ptBR":[0,"English for Locale"],"esLA":[0,"English for Locale"],"esES":[0,"Translated for Locale"],"enAU":[0,"No Page for Locale"],"enCA":[0,"No Page for Locale"],"enIN":[0,"No Page for Locale"],"enGB":[0,"English for Locale"],"idID":[0,"No Page for Locale"],"ruRU":[0,"English for Locale"],"svSE":[0,"No Page for Locale"],"viVN":[0,"No Page for Locale"],"plPL":[0,"English for Locale"],"arAR":[0,"No Page for Locale"],"nlNL":[0,"Translated for Locale"],"thTH":[0,"No Page for Locale"],"trTR":[0,"No Page for Locale"],"heIL":[0,"No Page for Locale"],"lvLV":[0,"No Page for Locale"],"etEE":[0,"No Page for Locale"],"ltLT":[0,"No Page for Locale"]}],"url":[0,"https://blog.cloudflare.com/threat-events-platform"],"metadata":[0,{"title":[0,"Cloudforce One 威胁事件平台 ——提供威胁行为者活动的增强上下文信息"],"description":[0,"通过我们全新的威胁事件平台,实时洞察不断变化的网络威胁形势。此工具为您的网络安全防御提供切实可行的情报,让您领先于攻击并保护您的关键资产。"],"imgPreview":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/59NiX2HVKYrXQXvraUj2Hj/cef9adfc20443592f330a08b18382b20/OG_Share_2024__9_.png"]}]}],"locale":[0,"zh-cn"],"translations":[0,{"posts.by":[0,"作者"],"footer.gdpr":[0,"GDPR"],"lang_blurb1":[0,"这篇博文也有 {lang1} 版本。"],"lang_blurb2":[0,"这篇博文也有 {lang1} 和{lang2}版本。"],"lang_blurb3":[0,"这篇博文也有 {lang1}、{lang2} 和{lang3}版本。"],"footer.press":[0,"新闻"],"header.title":[0,"Cloudflare 博客"],"search.clear":[0,"清除"],"search.filter":[0,"过滤"],"search.source":[0,"来源"],"footer.careers":[0,"招聘"],"footer.company":[0,"公司"],"footer.support":[0,"支持"],"footer.the_net":[0,"theNet"],"search.filters":[0,"过滤器"],"footer.our_team":[0,"我们的团队"],"footer.webinars":[0,"网络研讨会"],"page.more_posts":[0,"更多帖子"],"posts.time_read":[0,"{time} 分钟阅读时间"],"search.language":[0,"语言"],"footer.community":[0,"社区"],"footer.resources":[0,"资源"],"footer.solutions":[0,"解决方案"],"footer.trademark":[0,"商标"],"header.subscribe":[0,"订阅"],"footer.compliance":[0,"合规性"],"footer.free_plans":[0,"Free 计划"],"footer.impact_ESG":[0,"影响/ESG"],"posts.follow_on_X":[0,"在 X 上关注"],"footer.help_center":[0,"帮助中心"],"footer.network_map":[0,"网络地图"],"header.please_wait":[0,"请稍候"],"page.related_posts":[0,"相关帖子"],"search.result_stat":[0,"针对 {search_keyword} 的第 {search_range} 个搜索结果(共 {search_total} 个结果)"],"footer.case_studies":[0,"案例研究"],"footer.connect_2024":[0,"Connect 2024"],"footer.terms_of_use":[0,"服务条款"],"footer.white_papers":[0,"白皮书"],"footer.cloudflare_tv":[0,"Cloudflare TV"],"footer.community_hub":[0,"社区中心"],"footer.compare_plans":[0,"比较各项计划"],"footer.contact_sales":[0,"联系销售"],"header.contact_sales":[0,"联系销售团队"],"header.email_address":[0,"电子邮件地址"],"page.error.not_found":[0,"未找到页面"],"footer.developer_docs":[0,"开发人员文档"],"footer.privacy_policy":[0,"隐私政策"],"footer.request_a_demo":[0,"请求演示"],"page.continue_reading":[0,"继续阅读"],"footer.analysts_report":[0,"分析报告"],"footer.for_enterprises":[0,"企业级服务"],"footer.getting_started":[0,"开始使用"],"footer.learning_center":[0,"学习中心"],"footer.project_galileo":[0,"Project Galileo"],"pagination.newer_posts":[0,"较新的帖子"],"pagination.older_posts":[0,"较旧的帖子"],"posts.social_buttons.x":[0,"在 X 上讨论"],"search.icon_aria_label":[0,"搜索"],"search.source_location":[0,"来源/位置"],"footer.about_cloudflare":[0,"关于 Cloudflare"],"footer.athenian_project":[0,"Athenian Project"],"footer.become_a_partner":[0,"成为合作伙伴"],"footer.cloudflare_radar":[0,"Cloudflare Radar"],"footer.network_services":[0,"网络服务"],"footer.trust_and_safety":[0,"信任与安全"],"header.get_started_free":[0,"免费开始使用"],"page.search.placeholder":[0,"搜索 Cloudflare"],"footer.cloudflare_status":[0,"Cloudflare 状态"],"footer.cookie_preference":[0,"Cookie 首选项"],"header.valid_email_error":[0,"必须是有效的电子邮件地址。"],"search.result_stat_empty":[0,"显示第 {search_range} 个结果(共 {search_total} 个结果)"],"footer.connectivity_cloud":[0,"全球连通云"],"footer.developer_services":[0,"开发人员服务"],"footer.investor_relations":[0,"投资者关系"],"page.not_found.error_code":[0,"错误代码:404"],"search.autocomplete_title":[0,"请输入查询内容。按回车键发送"],"footer.logos_and_press_kit":[0,"标识与媒体资料包"],"footer.application_services":[0,"应用程序服务"],"footer.get_a_recommendation":[0,"获得推荐"],"posts.social_buttons.reddit":[0,"在 Reddit 上讨论"],"footer.sse_and_sase_services":[0,"SSE 和 SASE 服务"],"page.not_found.outdated_link":[0,"您可能使用了过期的链接,或者输入了错误的地址。"],"footer.report_security_issues":[0,"报告安全问题"],"page.error.error_message_page":[0,"抱歉,我们找不到您要打开的页面。"],"header.subscribe_notifications":[0,"订阅以接收新文章的通知:"],"footer.cloudflare_for_campaigns":[0,"Cloudflare for Campaigns"],"header.subscription_confimation":[0,"订阅已确认。感谢订阅!"],"posts.social_buttons.hackernews":[0,"在 Hacker News 上讨论"],"footer.diversity_equity_inclusion":[0,"多元、公平与包容"],"footer.critical_infrastructure_defense_project":[0,"关键基础设施防护项目"]}]}" ssr="" client="load" opts="{"name":"PostCard","value":true}" await-children="">