事件表格是安全中心內的詳細檢視,使用者可以在其中深入瞭解按各種條件篩選的特定威脅活動。在這裡,使用者可以使用 Cloudflare 的流量深入解析來探索特定的威脅事件和攻擊者活動。最重要的是,此表格將為我們的使用者提供可採取動作的入侵指標和事件摘要,以便他們能夠正確保護他們的服務。我們事件表格中的所有可用資料都可以透過 Cloudforce One 威脅事件 API 來存取。
為了展示威脅事件平台的強大力量,我們來看一個真實案例:
近期洩露的 Black Basta 犯罪集團聊天記錄揭露了有關其受害者、方法和基礎架構購買的詳細資料。雖然我們無法確認洩露的聊天記錄是否以任何方式被操縱,但聊天記錄中討論的基礎架構很容易驗證。因此,這項威脅情報現已作為事件呈現在威脅事件平台中,並附加 Cloudflare 獨有的背景資訊。
分析人員在搜尋 Black Basta 使用的網域、主機和檔案樣本時,可以利用威脅事件平台來取得有關該威脅行為者營運情況的寶貴見解。例如,在威脅事件 UI 中,使用者可以透過在下拉式清單中選擇「BlackBasta」來篩選「攻擊者」欄,如下圖所示。這將提供一份經過驗證的 IP 位址、網域名稱和檔案雜湊值清單,以供進一步調查。若要進一步瞭解 Cloudflare 有關 Black Basta 威脅活動的獨到見解,請參閱《Black Basta 出現重大失誤:利用該團體洩漏的聊天記錄》。
目前,Cloudforce One 客戶已經可以存取我們的 API 和儀表板,從而實現威脅情報與現有系統的無縫整合。此外,客戶很快就可獲得有關威脅事件的更多視覺化和分析工具,以便更好地理解和報告其調查發現。這一即將推出的使用者介面將包含攻擊者時間軸、攻擊活動概觀和攻擊圖表的增強視覺化,提供有關組織所面臨威脅的更深入見解。此外,我們將增加與現有 SIEM 平台整合和跨系統分享指標的功能。
"],"published_at":[0,"2025-03-18T13:10+00:00"],"updated_at":[0,"2025-03-19T16:37:07.969Z"],"feature_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2KDcMhcKUEFoFYIG1taRTs/e2ac7ad2205eda9d9fff64738816b32f/image3.png"],"tags":[1,[[0,{"id":[0,"3DmitkNK6euuD5BlhuvOLW"],"name":[0,"Security Week"],"slug":[0,"security-week"]}],[0,{"id":[0,"6Mp7ouACN2rT3YjL1xaXJx"],"name":[0,"安全性"],"slug":[0,"security"]}],[0,{"id":[0,"6hv2Z69PGr0qU411KfQNUE"],"name":[0,"威脅情報"],"slug":[0,"threat-intelligence"]}],[0,{"id":[0,"3GUtnWmux4qZOUh5OjIljE"],"name":[0,"Cloudforce One"],"slug":[0,"cloudforce-one"]}],[0,{"id":[0,"HkD3go6gAP2HK3M4NzrLz"],"name":[0,"Intel"],"slug":[0,"intel"]}],[0,{"id":[0,"1PvAU8aG8p8SvdOGMPtDnO"],"name":[0,"威脅"],"slug":[0,"threats"]}],[0,{"id":[0,"4geXkm5R255jIxA8W3E1bP"],"name":[0,"背景資訊"],"slug":[0,"context"]}]]],"relatedTags":[0],"authors":[1,[[0,{"name":[0,"Alexandra Moraru"],"slug":[0,"alexandra"],"bio":[0,null],"profile_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/URwbDrA0k9GNtNsCsAC7N/930223a35d0c7a39cb843e44f530ccba/alexandra.png"],"location":[0,"London"],"website":[0,null],"twitter":[0,"@alexandramoraru"],"facebook":[0,null]}],[0,{"name":[0,"Blake Darché"],"slug":[0,"blake"],"bio":[0,"Head of Threat Intelligence @ Cloudflare. Former CSO/Co-Founder @ Area 1 Security. Former Incident Response @ CrowdStrike. Former Analyst @ National Security Agency."],"profile_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4bZNxcx9X9SxXvCtiKTmoX/b155cbc0977be2f3ba5a443f19fb692a/blake.jpeg"],"location":[0,null],"website":[0,null],"twitter":[0,"@blakedarche"],"facebook":[0,null]}],[0,{"name":[0,"Emilia Yoffie"],"slug":[0,"emilia-yoffie"],"bio":[0],"profile_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6nc5p2ESsweibmVZ4PzKiM/964fd97363e7365df76c497baee3ee40/Emilia_Yoffie.jpg"],"location":[0],"website":[0],"twitter":[0],"facebook":[0]}]]],"meta_description":[0,"透過我們全新的威脅事件平台,即時瞭解不斷變化的網路威脅形勢。此工具為您的網路安全防禦提供切實可行的情報,讓您領先於攻擊並保護您的關鍵資產。"],"primary_author":[0,{}],"localeList":[0,{"name":[0,"Blog LL - Unleashing improved context for threat actor activity with our Cloudforce One threat events platform"],"enUS":[0,"English for Locale"],"zhCN":[0,"Translated for Locale"],"zhHansCN":[0,"No Page for Locale"],"zhTW":[0,"Translated for Locale"],"frFR":[0,"Translated for Locale"],"deDE":[0,"Translated for Locale"],"itIT":[0,"English for Locale"],"jaJP":[0,"Translated for Locale"],"koKR":[0,"Translated for Locale"],"ptBR":[0,"English for Locale"],"esLA":[0,"English for Locale"],"esES":[0,"Translated for Locale"],"enAU":[0,"No Page for Locale"],"enCA":[0,"No Page for Locale"],"enIN":[0,"No Page for Locale"],"enGB":[0,"English for Locale"],"idID":[0,"No Page for Locale"],"ruRU":[0,"English for Locale"],"svSE":[0,"No Page for Locale"],"viVN":[0,"No Page for Locale"],"plPL":[0,"English for Locale"],"arAR":[0,"No Page for Locale"],"nlNL":[0,"Translated for Locale"],"thTH":[0,"No Page for Locale"],"trTR":[0,"No Page for Locale"],"heIL":[0,"No Page for Locale"],"lvLV":[0,"No Page for Locale"],"etEE":[0,"No Page for Locale"],"ltLT":[0,"No Page for Locale"]}],"url":[0,"https://blog.cloudflare.com/threat-events-platform"],"metadata":[0,{"title":[0,"透過我們的 Cloudforce One 威脅事件平台,揭示威脅行為者活動的更多背景資訊"],"description":[0,"透過我們全新的威脅事件平台,即時瞭解不斷變化的網路威脅形勢。此工具為您的網路安全防禦提供切實可行的情報,讓您領先於攻擊並保護您的關鍵資產。"],"imgPreview":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/59NiX2HVKYrXQXvraUj2Hj/cef9adfc20443592f330a08b18382b20/OG_Share_2024__9_.png"]}]}],"locale":[0,"zh-tw"],"translations":[0,{"posts.by":[0,"作者:"],"footer.gdpr":[0,"GDPR"],"lang_blurb1":[0,"本貼文還提供以下語言版本:{lang1}。"],"lang_blurb2":[0,"本貼文還提供以下語言版本:{lang1} 和{lang2}。"],"lang_blurb3":[0,"本貼文還提供以下語言版本:{lang1},{lang2} 和{lang3}。"],"footer.press":[0,"新聞"],"header.title":[0,"Cloudflare 部落格"],"search.clear":[0,"清除"],"search.filter":[0,"篩選"],"search.source":[0,"來源"],"footer.careers":[0,"人才招募"],"footer.company":[0,"公司"],"footer.support":[0,"支援"],"footer.the_net":[0,"theNet"],"search.filters":[0,"篩選器"],"footer.our_team":[0,"我們的團隊"],"footer.webinars":[0,"網路研討會"],"page.more_posts":[0,"更多貼文"],"posts.time_read":[0,"閱讀時間:{time} 分鐘"],"search.language":[0,"語言"],"footer.community":[0,"社群"],"footer.resources":[0,"資源"],"footer.solutions":[0,"解決方案"],"footer.trademark":[0,"商標"],"header.subscribe":[0,"訂閱"],"footer.compliance":[0,"合規性"],"footer.free_plans":[0,"免費方案"],"footer.impact_ESG":[0,"影響力/ESG"],"posts.follow_on_X":[0,"在 X 上進行關注"],"footer.help_center":[0,"幫助中心"],"footer.network_map":[0,"網路分佈圖"],"header.please_wait":[0,"請稍候"],"page.related_posts":[0,"相關貼文"],"search.result_stat":[0,"針對 {search_keyword} 的第 {search_range} 個搜尋結果(共 {search_total} 個結果)"],"footer.case_studies":[0,"案例研究"],"footer.connect_2024":[0,"Connect 2024"],"footer.terms_of_use":[0,"服務條款"],"footer.white_papers":[0,"白皮書"],"footer.cloudflare_tv":[0,"Cloudflare TV"],"footer.community_hub":[0,"社群中心"],"footer.compare_plans":[0,"比較各項方案"],"footer.contact_sales":[0,"連絡銷售團隊"],"header.contact_sales":[0,"連絡銷售團隊"],"header.email_address":[0,"電子郵件地址"],"page.error.not_found":[0,"找不到頁面"],"footer.developer_docs":[0,"開發人員文件"],"footer.privacy_policy":[0,"隱私權原則"],"footer.request_a_demo":[0,"請求示範"],"page.continue_reading":[0,"繼續閱讀"],"footer.analysts_report":[0,"分析報告"],"footer.for_enterprises":[0,"企業適用"],"footer.getting_started":[0,"開始使用"],"footer.learning_center":[0,"學習中心"],"footer.project_galileo":[0,"Galileo 專案"],"pagination.newer_posts":[0,"較新貼文"],"pagination.older_posts":[0,"較舊貼文"],"posts.social_buttons.x":[0,"在 X 上進行討論"],"search.icon_aria_label":[0,"搜尋"],"search.source_location":[0,"來源/地點"],"footer.about_cloudflare":[0,"關於 Cloudflare"],"footer.athenian_project":[0,"Athenian 專案"],"footer.become_a_partner":[0,"成為合作夥伴"],"footer.cloudflare_radar":[0,"Cloudflare Radar"],"footer.network_services":[0,"網路服務"],"footer.trust_and_safety":[0,"信任和安全"],"header.get_started_free":[0,"免費開始使用"],"page.search.placeholder":[0,"搜尋 Cloudflare"],"footer.cloudflare_status":[0,"Cloudflare 狀態"],"footer.cookie_preference":[0,"Cookie 喜好設定"],"header.valid_email_error":[0,"必須是有效電子郵件。"],"search.result_stat_empty":[0,"第 {search_range} 筆搜尋結果(共 {search_total} 筆)"],"footer.connectivity_cloud":[0,"全球連通雲"],"footer.developer_services":[0,"開發人員服務"],"footer.investor_relations":[0,"投資人關係"],"page.not_found.error_code":[0,"錯誤代碼:404"],"search.autocomplete_title":[0,"插入查詢。按下 Enter 鍵即可傳送"],"footer.logos_and_press_kit":[0,"標誌與新聞資料包"],"footer.application_services":[0,"應用程式服務"],"footer.get_a_recommendation":[0,"取得建議"],"posts.social_buttons.reddit":[0,"在 Reddit 上進行討論"],"footer.sse_and_sase_services":[0,"SSE 和 SASE 服務"],"page.not_found.outdated_link":[0,"您可能使用了過時的連結,或者可能輸入了錯誤的位址。"],"footer.report_security_issues":[0,"報告網路安全問題"],"page.error.error_message_page":[0,"抱歉,我們找不到您想要的頁面。"],"header.subscribe_notifications":[0,"訂閱以接收新文章的通知:"],"footer.cloudflare_for_campaigns":[0,"Cloudflare for Campaigns"],"header.subscription_confimation":[0,"訂閱已確認。感謝訂閱!"],"posts.social_buttons.hackernews":[0,"在 Hacker News 上進行討論"],"footer.diversity_equity_inclusion":[0,"多樣性、公平性和包容性"],"footer.critical_infrastructure_defense_project":[0,"關鍵基礎架構防禦專案"]}]}" ssr="" client="load" opts="{"name":"PostCard","value":true}" await-children="">