Full Report
Cloudflare Managed Defense uses a team of specialized AI agents built on Workers and global network telemetry to analyze security alerts. By separating deterministic evidence collection from model inference, the system delivers grounded recommendations to Managed Defense Analysts.
Analysis Summary
# Best Practices: Evidence-Grounded Agentic Security Operations
## Overview
These practices address the "Alert Paradox"—the overwhelming volume of security telemetry that leads to analyst burnout and missed incidents. By utilizing a multi-agent AI harness, organizations can automate evidence collection and initial triage, ensuring that human analysts focus on resolution rather than data gathering.
## Key Recommendations
### Immediate Actions
1. **Decouple Collection from Inference:** Use deterministic code (standard API calls) to gather evidence before involving AI. Do not allow AI agents to fetch their own raw data to avoid hallucinations.
2. **Implement Versioned Snapshots:** Store every piece of reconnaissance data with a source, version, and timestamp to ensure investigations are reproducible.
3. **Establish Data Boundaries:** Hard-code the scope (account IDs, time ranges, and sources) in application code rather than relying on LLM prompts to maintain security boundaries.
### Short-term Improvements (1-3 months)
1. **Deploy Specialist AI Agents:** Instead of one general-purpose bot, use specialized agents for distinct tasks (e.g., one for Traffic Analysis, one for Threat Intel, one for Policy Evaluation).
2. **Filter Noise at the Edge:** Implement a lightweight triage model (like Cloudflare's *Clef*) to score alerts based on historical decisions and baseline behavior before they reach a human.
3. **Formalize State Reporting:** Require systems to distinguish between "Not checked," "Checked/No result," and "Checked/Evidence of absence" to prevent incomplete data from being interpreted as a "clean" status.
### Long-term Strategy (3+ months)
1. **Adopt an "Agentic Advisory" Model:** Move toward a system where AI generates specific remediation code (e.g., WAF rules, rate-limiting signatures) that humans only need to review and approve.
2. **Continuous Monitoring Agents:** Transition from reactive alert-based triggers to continuous AI agents that monitor traffic patterns to identify anomalies that fixed rules might miss.
## Implementation Guidance
### For Small Organizations
- **Leverage Managed Services:** Utilize built-in AI tools from your edge providers (like Cloudflare Managed Defense) rather than building custom agent harnesses.
- **Focus on Defaults:** Enable automated DDoS and WAF protections that use pre-trained decision models.
### For Medium Organizations
- **Integrate Global Telemetry:** Ensure your security tools ingest external threat intelligence to compare internal alerts against global attack trends.
- **Human-in-the-loop (HITL):** Use AI to draft recommendations, but keep a human gatekeeper for any rule changes or traffic blocks.
### For Large Enterprises
- **Multi-Model Redundancy:** Use a variety of models (e.g., GPT-5.6 Cyber, Mythos) to cross-validate findings for critical incidents.
- **Zero-Trust for Agents:** Treat AI agents as untrusted users; do not grant them authority to cross tenant boundaries or act autonomously without human authorization.
## Configuration Examples
While specific code is proprietary, the harness follows this architectural flow:
1. **Input:** Security Event (e.g., WAF Block).
2. **Deterministic Recon:** `GET /api/v4/zones/{id}/security/events` (Fixed time range).
3. **Specialist Agent Call:** `Prompt: [Recon Data] + [Specialist Role Instructions]`.
4. **Consolidation:** Aggregate specialist outputs into a single JSON advisory for the analyst.
## Compliance Alignment
- **NIST Cybersecurity Framework (CSF):** Aligns with *Detect* (Continuous Monitoring) and *Respond* (Analysis) functions.
- **ISO/IEC 27001:** Supports operational security and incident management requirements.
- **CIS Controls:** Specifically addresses Control 08 (Audit Log Management) and Control 17 (Incident Response Management).
## Common Pitfalls to Avoid
- **Context Flattening:** Treating detector descriptions and raw telemetry as equal authority. Detections are hypotheses, not facts.
- **Silent Failures:** Assuming a timeout or missing metadata means "no threat."
- **Prompt Drift:** Expecting a prompt to prevent an AI from looking at the wrong data source; always enforce scope at the API layer.
## Resources
- **Cloudflare Managed Defense:** [https://www.cloudflare.com/managed-defense/](https://www.cloudflare.com/managed-defense/)
- **Clef Decision Models:** [https://blog.cloudflare.com/clef-decision-models/](https://blog.cloudflare.com/clef-decision-models/)
- **OpenAI Daybreak Defense Network:** [https://openai[.]com/daybreak/](https://openai.com/daybreak/)