Use Security Analytics > Attack Analysis to investigate attack signature matches before applying mitigation.
-
In the Cloudflare dashboard, go to Security > Analytics.
Go to Analytics ↗ -
Select Attack Analysis.
-
Choose the time range and application scope to investigate.
-
Plot request volume over time by signature Ref, category, or WAF Attack Score.
-
Compare high- and low-confidence matches.
-
Filter by request outcome to identify mitigated and unmitigated traffic.
-
Narrow the analysis by hostname, path, method, category, CVE, or signature Ref.
-
Review representative requests before creating or changing a Security Rule.
Use this analysis to identify common signatures and attack categories. You can also investigate a specific Common Vulnerabilities and Exposures (CVE) identifier or attack technique. Correlate the matches with WAF Attack Score to add another signal.
The request outcome shows whether existing protections mitigated matching traffic. It also helps identify requests served by Cloudflare or your origin. A detection does not apply an action by itself.
Confidence describes the expected false-positive characteristics of a signature. It does not prove that a request is malicious.
| Confidence | Meaning | Comparison with Managed Rules | Recommended analysis |
|---|---|---|---|
high |
The signature targets a high true-positive and low false-positive rate. | Includes the same signatures that the default Managed Rules deployment enables. | Confirm affected traffic and current mitigation before applying a broad action. |
low |
The signature has a greater risk of matching legitimate application traffic. | Includes the Managed Rules signatures that are disabled by default. | Review requests and scope mitigation to the affected application surface. |
Legitimate rich-text input can match a generic cross-site scripting signature. For example, a content management or support application may accept HTML.
Filter the analysis to that hostname, path, and method. Review representative requests to distinguish expected content from attacks. Then create a scoped rule or exception instead of changing protection for the entire application.
Each signature Ref matches the corresponding Managed Rule public Rule ID. Use this identifier to find the Managed Rule and compare the detection with your deployment.
Check the request outcome and Security Events before assuming Managed Rules blocked a match. Managed Rules actions and overrides determine their behavior.
Attack Analysis uses Security Analytics adaptive sampling. Use Log Explorer when you need 100% retention rather than sampled data.
After reviewing historical traffic, refer to Use attack signatures in Security Rules.