Skip to content

Security settings

Last updated View as MarkdownAgent setup

This page describes the security settings available in the new security dashboard for a given domain.

To access security settings in the new security dashboard, go to the Settings page.

Go to Settings ↗

Security setting categories

Security settings and detection tools are categorized by the type of threat that they detect and mitigate.

Web application exploits

In the Web application exploits security category you can manage the following settings:

Refer to each linked page for details.

DDoS attacks

The DDoS attacks security category shows the multiple mitigation services against DDoS attacks provided by Cloudflare.

You can create rules to override DDoS attack protection tools. DDoS attack protection overrides are only available to Enterprise customers with the Advanced DDoS Protection subscription.

To learn more about DDoS protection overrides, refer to the following resources:

Additionally, you can manage the following settings:

Bot traffic

In the Bot traffic security category you can manage the following settings:

API abuse

In the API abuse security category you can manage the following settings:

Client-side abuse

In the Client-side abuse security category you can manage the following settings:

All settings

The following table links to additional information about each available setting:

Setting Location in previous dashboard navigation
AI Labyrinth Security > Bots > Configure Bot Fight Mode
Security
> Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
AI Security for Apps N/A
Block AI Bots Security > Bots > Configure Bot Fight Mode
Security
> Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
Bot Management: Security > Bots
— JS detections Security > Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
— Auto-update machine learning Security > Bots > Configure Bot Management
Browser integrity check Security > Settings
Challenge Passage: Timeout Security > Settings
Client certificates SSL > Client Certificates
Cloudflare managed ruleset Security > WAF > Managed rules tab
Continuous script monitoring: Security > Client-side security
— Reporting endpoint Security > Client-side security > Settings
— Data processing Security > Client-side security > Settings
— Alerts Security > Client-side security > Settings
Account Home > Notifications
Create a developer portal Security > API Shield > Settings
Custom fallthrough rules Security > API Shield > Settings
Email Address Obfuscation Scrape Shield
API endpoint discovery: API Shield > Discovery
— Session identifiers Security > API Shield > Settings
Endpoint labels Security > Settings > Labels
Hotlink Protection Scrape Shield
HTTP DDoS attack protection: Security > DDoS
— Configure overrides Security > DDoS
Instruct AI bot traffic with robots.txt Security > Bots > Configure Bot Fight Mode
Security
> Bots > Configure Super Bot Fight Mode
Security
> Bots > Configure Bot Management
IP access rules Security > WAF > Tools tab
Security > WAF > Custom rules tab
IP lists Account Home > Manage Account > Configurations
JWT validation: Security > API Shield > Settings
— JWT validation rules Security > API Shield > API Rules
— Token configurations Security > API Shield > Settings
Leaked credentials detection: Security > Settings
— Custom username and password location Security > Settings
Malicious uploads detection: Security > Settings
— Custom content location Security > Settings
mTLS rules SSL/TLS > Client Certificates
Network-layer DDoS attack protection Account Home > L3/4 DDoS > Network-layer DDoS Protection
OWASP Core ruleset Security > WAF > Managed rules tab
Rate limit authentication requests Security > WAF > Rate limiting rules tab
Replace insecure JavaScript libraries Security > Settings
Schema learning: Security > Web Assets > Operations
— Session identifiers Security > API Shield > Settings
Schema validation Security > API Shield > Schema Validation
— Operations Security > Web Assets > Operations
— Active schemas Security > API Shield > Schema Validation
Security level: I'm under attack mode Security > Settings
Security.txt Security > Settings
Sensitive data detection ruleset Security > Sensitive Data
Sequence detection: Security > API Shield > API Rules
— Endpoints Security > API Shield
— Session identifiers Security > API Shield > Settings
Session identifiers Security > API Shield > Settings
SSL/TLS DDoS attack protection Security > DDoS
Token configurations Security > API Shield > Settings
User agent blocking Security > WAF > Tools tab
Security > WAF > Custom rules tab
Zone lockdown Security > WAF > Tools tab
Security > WAF > Custom rules tab

Was this helpful?