elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
30 stars 447 forks source link

[New Integration] Cloudflare Email Security #11163

Open cpascale43 opened 2 months ago

cpascale43 commented 2 months ago

Description

Cloudflare Email Security monitors email traffic for various threats including phishing, malware and spam. It provides protection by intercepting and quarantining potentially malicious emails before they are delivered to users' inboxes.

The Elastic integration ingests security events from Cloudflare Email Security, enabling users to correlate email threats with other security events across their organization's environment.

Architecture

Email Security events are delivered via Cloudflare's Alert Webhooks feature: https://developers.cloudflare.com/email-security/email-configuration/domains-and-routing/alert-webhooks/

Refer to the Cloudflare documentation for more details: https://developers.cloudflare.com/email-security/

Dashboard Ideas

The dashboard should provide visibility into email-based threats and security events detected by Cloudflare. It enables real-time monitoring of phishing attempts, malware distribution, and spam campaigns to help security teams quickly identity and respond to email-based attacks. Key categories, and suggested visualizations are:

Integration release checklist

This checklist is intended for integrations maintainers to ensure consistency when creating or updating a Package, Module or Dataset for an Integration.

All changes

elasticmachine commented 2 months ago

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)