INTEGRITY Cloudflare Docs

Example rules

Custom rule and rate limiting rule examples using threat intelligence fields. All fields are arrays — use any() with [*].

Log matches before blocking

Deploy with Log (Enterprise plans) to review matches before enforcing:

Review matches in Security Events, then change the action to Block or Managed Challenge.

Block DDoS participants targeting your region

Challenge a threat actor targeting the finance sector

Filter by attacker country

Combine with attack score

Block requests flagged by the WAF threat intelligence dataset that also have a low attack score:

Rate limit threat actors on API paths

Rate limiting rule applying a stricter rate to flagged IPs on your API: