Your security tools generate thousands of alerts a day. How many actually get investigated? Flarehawk does it for you. Real-time threat detection, automated investigation, and one-click fixes. Our ML engine builds a model unique to your environment and gets smarter every day. 5-year log retention, SSO, Slack integration, all built-in. Starting with Cloudflare Enterprise. Now in open beta.
When we started building Flarehawk, the hardest problem wasn't detection, it was context. Most security tools can tell you something happened. Very few can tell you why it matters in your environment.
That's why we built the Flarehawk Fabric. It's a per-tenant ML model that ingests your logs, learns your baseline behaviors, and scores anomalies against what's normal for you, not some generic threshold. Every customer gets their own model. It evolves continuously.
Give it a try and tell us your thoughts!
By the way, just a quick update! While we only supported Cloudflare Enterprise via Logpush for now, we are about to ship support for all Cloudflare plans via a custom Worker middleware.
Also, Microsoft 365, Google Workspace, Okta, and more ingestion connections coming in the next few days!
Report
@ilyasesmail Congrats on your launch! What metrics do you track to measure the effectiveness of your threat monitoring?
@kimberly_ross thanks for your comment! We monitor false positive rates, and do both human and AI-powered false positive detection. Our goal is for false positives to be <5% of all alerts generated, and not all alerts go on to trigger incidents, so the incident false positive should be much closer to <1%.
After we apply any remediation measures (WAF rules, rate limiting rules, etc), we monitor the traffic response in terms of actual dissipation of threat traffic, allowing for quick rollback, all through the Flarehawk dashboard.
Report
Congratulations on your launch!
I had a question, does it only ingest logs and show analytics based on the same or is there any provision for metrics and monitors like Datadog and LogMint?
@shreya_srivastava17 thanks for the comment! We currently ingest logs and show analytics based on those logs, which do include more detail and granularity than you'd find in the Cloudflare dashboard for example. Part of the reason why is that we do not do log sampling, meaning we ingest, store and report on every single log.
We are building out custom monitors and custom dashboards, and I'll prioritize that in our roadmap! We're also going to announce a few more additions to help you query and analyze the data we've ingested 👀 keep an eye out!
Flarehawk
Flarehawk
By the way, just a quick update! While we only supported Cloudflare Enterprise via Logpush for now, we are about to ship support for all Cloudflare plans via a custom Worker middleware.
Also, Microsoft 365, Google Workspace, Okta, and more ingestion connections coming in the next few days!
@ilyasesmail Congrats on your launch! What metrics do you track to measure the effectiveness of your threat monitoring?
Flarehawk
@kimberly_ross thanks for your comment! We monitor false positive rates, and do both human and AI-powered false positive detection. Our goal is for false positives to be <5% of all alerts generated, and not all alerts go on to trigger incidents, so the incident false positive should be much closer to <1%.
After we apply any remediation measures (WAF rules, rate limiting rules, etc), we monitor the traffic response in terms of actual dissipation of threat traffic, allowing for quick rollback, all through the Flarehawk dashboard.
Flarehawk
@shreya_srivastava17 thanks for the comment! We currently ingest logs and show analytics based on those logs, which do include more detail and granularity than you'd find in the Cloudflare dashboard for example. Part of the reason why is that we do not do log sampling, meaning we ingest, store and report on every single log.
We are building out custom monitors and custom dashboards, and I'll prioritize that in our roadmap! We're also going to announce a few more additions to help you query and analyze the data we've ingested 👀 keep an eye out!