---
title: "Threat defense"
description: "Detect and respond to threats in Calico Cloud connected clusters with threat intelligence feeds, deep packet inspection, and WAF."
product: "Calico Cloud"
version: "v23.0.1"
section: "Threat defense"
canonical_url: "https://docs.tigera.io/calico-cloud/threat/"
---

# Threat defense

Use real-time monitoring to detect and block threats to your cluster.

##### [Security event management](https://docs.tigera.io/calico-cloud/threat/security-event-management.md)

[Triage and manage security events from Calico Cloud connected clusters in the Security Events Dashboard, with filtering, exceptions, and recommended remediation.](https://docs.tigera.io/calico-cloud/threat/security-event-management.md)

##### [Trace and alert on suspicious domains](https://docs.tigera.io/calico-cloud/threat/suspicious-domains.md)

[Add threat intelligence feeds to Calico Cloud to detect DNS queries to suspicious domains from connected clusters and surface impacted pods in the anomaly dashboard.](https://docs.tigera.io/calico-cloud/threat/suspicious-domains.md)

##### [Trace and block suspicious IPs](https://docs.tigera.io/calico-cloud/threat/suspicious-ips.md)

[Add threat intelligence feeds to Calico Cloud to alert on flows to suspicious IPs in connected clusters and optionally block them with a dynamic deny-list policy.](https://docs.tigera.io/calico-cloud/threat/suspicious-ips.md)

##### [Workload-based Web Application Firewall (WAF)](https://docs.tigera.io/calico-cloud/threat/web-application-firewall.md)

[Protect cluster workloads from Layer 7 attacks with the Calico Cloud workload-based WAF, powered by Envoy sidecars and the OWASP ModSecurity Core Rule Set.](https://docs.tigera.io/calico-cloud/threat/web-application-firewall.md)

##### [Webhooks for security events](https://docs.tigera.io/calico-cloud/threat/configuring-webhooks.md)

[Configure Calico Cloud webhooks from the web console to post security event alerts to Slack, Jira, Alertmanager, or generic JSON endpoints.](https://docs.tigera.io/calico-cloud/threat/configuring-webhooks.md)

##### [Deploy a web application firewall with Calico Ingress Gateway](https://docs.tigera.io/calico-cloud/threat/deploying-waf-ingress-gateway.md)

[Step-by-step tutorial for deploying a Calico Cloud web application firewall with the Calico Ingress Gateway to protect publicly exposed services from Layer 7 attacks.](https://docs.tigera.io/calico-cloud/threat/deploying-waf-ingress-gateway.md)

##### [Deep packet inspection](https://docs.tigera.io/calico-cloud/threat/deeppacketinspection.md)

[Run deep packet inspection on selected workloads in Calico Cloud connected clusters with Snort community rules to alert on suspected malicious traffic.](https://docs.tigera.io/calico-cloud/threat/deeppacketinspection.md)

##### [Anonymization attacks](https://docs.tigera.io/calico-cloud/threat/tor-vpn-feed-and-dashboard.md)

[Detect anonymization activity in Calico Cloud connected clusters with Tor bulk exit and X4B VPN feeds, and investigate findings in the Tor-VPN dashboard in the web console.](https://docs.tigera.io/calico-cloud/threat/tor-vpn-feed-and-dashboard.md)
