← Cloudflare SecurityCONTENT HISTORY

Update to Cloudflare Security

Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "monitoring-incident-response",
  "description": "Assess security observability and guide response to Cloudflare account, token, application, or data incidents.",
  "included_files": [],
  "skill_md_contents": "---\nname: monitoring-incident-response\ndescription: Assess security observability and guide response to Cloudflare account, token, application, or data incidents.\n---\n\n# Monitoring and Incident Response\n\nReview available security insights, audit events, Access events, WAF/API signals, Worker logs, deployment events, alerting, retention, and ownership. Check whether logs may contain authorization headers, cookies, tokens, presigned URLs, personal data, or request bodies. Do not reproduce sensitive values. Distinguish missing telemetry from absence of attack.\n\nFor suspected compromise, prioritize containment with the account owner: secure identity/email, revoke affected sessions, rotate/revoke exposed credentials, restrict access, preserve relevant logs, assess changes and data access, restore trusted deployments, and notify required stakeholders under applicable policy. Tailor sequence to avoid lockout and service destruction. Do not disable resources, delete evidence, or rotate credentials on the user's behalf without explicit action-specific approval. Include an incident timeline and unknowns where evidence allows.\n"
}

SHA-256: 6b4835ecdd177c3296b01e7d37609825255d7a2a2981ea770f16defb35c54a85