Back

Security ·2025 · Live

Active response: Wazuh blocking at Cloudflare

Integration wiring Wazuh alerts to the Cloudflare API to block attacking IPs at the edge, before they ever reach the server.

Detecting an attack you cannot stop until the next morning is half the job. This integration closes the loop: when Wazuh fires an alert at the configured severity, an active-response script calls the Cloudflare API and adds the source IP to a block rule.

The block happens at Cloudflare's edge, so malicious traffic never consumes bandwidth or CPU on the origin server.

Highlights

  • Wazuh active response wired to the Cloudflare API
  • Edge blocking, without touching the origin firewall
  • Configurable severity threshold to avoid false positives
  • Wazuh published behind Caddy with TLS

Stack

  • Wazuh
  • Cloudflare API
  • Bash
  • Python
  • Caddy
  • Docker

Private repository — Code available on request

Sections

Actions