← Cloudflare SecurityCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Cloudflare Security
Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "monitoring-incident-response",
"description": "Assess security observability and guide response to Cloudflare account, token, application, or data incidents.",
"included_files": [],
"skill_md_contents": "---\nname: monitoring-incident-response\ndescription: Assess security observability and guide response to Cloudflare account, token, application, or data incidents.\n---\n\n# Monitoring and Incident Response\n\nReview available security insights, audit events, Access events, WAF/API signals, Worker logs, deployment events, alerting, retention, and ownership. Check whether logs may contain authorization headers, cookies, tokens, presigned URLs, personal data, or request bodies. Do not reproduce sensitive values. Distinguish missing telemetry from absence of attack.\n\nFor suspected compromise, prioritize containment with the account owner: secure identity/email, revoke affected sessions, rotate/revoke exposed credentials, restrict access, preserve relevant logs, assess changes and data access, restore trusted deployments, and notify required stakeholders under applicable policy. Tailor sequence to avoid lockout and service destruction. Do not disable resources, delete evidence, or rotate credentials on the user's behalf without explicit action-specific approval. Include an incident timeline and unknowns where evidence allows.\n"
}SHA-256: 6b4835ecdd177c3296b01e7d37609825255d7a2a2981ea770f16defb35c54a85