# CyberSecure by Proofpoint and Cloudflare - Unifi Intrusion Prevention

**URL:** https://community.emergingthreats.net/t/cybersecure-by-proofpoint-and-cloudflare-unifi-intrusion-prevention/2905
**Category:** Wiki
**Tags:** unifi
**Created:** [July 17, 2025, 8:48pm UTC](https://community.emergingthreats.net/t/cybersecure-by-proofpoint-and-cloudflare-unifi-intrusion-prevention/2905 "2025-07-17T20:48:56Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)
#### Post date: [July 17, 2025, 8:48pm UTC](https://community.emergingthreats.net/t/cybersecure-by-proofpoint-and-cloudflare-unifi-intrusion-prevention/2905/1 "2025-07-17T20:48:56Z")

</div>

# Introduction:

CyberSecure is a service that is available on several Ubiquiti Unifi appliances including the Cloud Gateway devices which are popular within SOHO environments. CyberSecure consists of multiple detection methods which are powered by Cloudflare, Proofpoint, and the Unifi Appliance.

* * *

# Detection Services:

## Cloudflare

- Content Filtering of Malicious/Adult Content Domains
- AdBlocking

## Unifi

- Region Blocking
- Encrypted DNS
- Honeypot

## Proofpoint / Emerging Threats

- Intrusion Prevention
- ET/ETPRO Rulesets

This is what the CyberSecure Configuration settings look like on the Cloud Gateway Control Pane.

 ![Screenshot 2025-07-17 at 4.01.21 PM](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/2X/9/90bbd71c9d53691b9fc472adfde67903683cede3.png)

* * *

# Which Rules Are Enabled?

Unless you subscribe to “ **CyberSecure Enhanced** ” (which includes ETPRO rules) your appliance will download the standard “ET OPEN” ruleset which is free and available for download [here.](https://rules.emergingthreats.net/) The ruleset is grouped into categories for fine-tuned control. Once Intrusion Prevention is enabled, administrators can select the categories relevant to their environment. Unifi summarizes Emerging Threats rulesets into similar groups so it isn’t immediately clear from the web interface which categories are applied but the console logs will reveal which rules are enabled.

The subsets for each category can be downloaded [here.](https://rules.emergingthreats.net/open/suricata-7.0.3/rules/)

 ![Screenshot 2025-07-17 at 2.06.40 PM](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/2X/a/ab4c9715954ca7ae1ba734d16a917e8f517af813.png)

## Console Output (Cleaned Up For Readability)

```auto
"ACTIVEX" then signature<FILTERED> = "emerging-activex"
"ADWARE_PUP" then signature<FILTERED> = ""
"ATTACK_RESPONSE" then signature<FILTERED> = "emerging-attackresponse"
"BOTCC" then signature<FILTERED> = "botcc"
"BOTCC.PORTGROUPED" then signature<FILTERED> = "botcc-portgrouped"
"CHAT" then signature<FILTERED> = "emerging-chat"
"CIARMY" then signature<FILTERED> = "ciarmy"
"COINMINER" then signature<FILTERED> = ""
"COMPROMISED" then signature<FILTERED> = "compromised"
"CURRENT_EVENTS" then signature<FILTERED> = ""
"DELETED" then signature<FILTERED> = ""
"DNS" then signature<FILTERED> = "emerging-dns"
"DOS" then signature<FILTERED> = "emerging-dos"
"DROP" then signature<FILTERED> = ""
"DSHIELD" then signature<FILTERED> = "dshield"
"EXPLOIT" then signature<FILTERED> = "emerging-exploit"
"EXPLOIT_KIT" then signature<FILTERED> = ""
"FTP" then signature<FILTERED> = "emerging-ftp"
"GAMES" then signature<FILTERED> = "emerging-games"
"HUNTING" then signature<FILTERED> = ""
"ICMP" then signature<FILTERED> = "emerging-icmp"
"ICMP_INFO" then signature<FILTERED> = "emerging-icmpinfo"
"IMAP" then signature<FILTERED> = "emerging-imap"
"INAPPROPRIATE" then signature<FILTERED> = "emerging-inappropriate"
"INFO" then signature<FILTERED> = "emerging-info"
"JA3" then signature<FILTERED> = ""
"MALWARE" then signature<FILTERED> = "emerging-malware"
"MISC" then signature<FILTERED> = "emerging-misc"
"MOBILE_MALWARE" then signature<FILTERED> = "emerging-mobile"
"NETBIOS" then signature<FILTERED> = "emerging-netbios"
"P2P" then signature<FILTERED> = "emerging-p2p"
"PHISHING" then signature<FILTERED> = ""
"POLICY" then signature<FILTERED> = "emerging-policy"
"POP3" then signature<FILTERED> = "emerging-pop3"
"RPC" then signature<FILTERED> = "emerging-rpc"
"SCADA" then signature<FILTERED> = "emerging-scada"
"SCADA_SPECIAL" then signature<FILTERED> = ""
"SCAN" then signature<FILTERED> = "emerging-scan"
"SHELLCODE" then signature<FILTERED> = "emerging-shellcode"
"SMTP" then signature<FILTERED> = "emerging-smtp"
"SNMP" then signature<FILTERED> = "emerging-snmp"
"SQL" then signature<FILTERED> = "emerging-sql"
"TELNET" then signature<FILTERED> = "emerging-telnet"
"TFTP" then signature<FILTERED> = "emerging-tftp"
"THREATVIEW_CS_C2" then signature<FILTERED> = ""
"TOR" then signature<FILTERED> = "tor"
"user<FILTERED>" then signature<FILTERED> = "emerging-user<FILTERED>"
"VOIP" then signature<FILTERED> = "emerging-voip"
"WEB_CLIENT" then signature<FILTERED> = "emerging-webclient"
"WEB_SERVER" then signature<FILTERED> = "emerging-webserver"
"WEB_SPECIFIC_APPS" then signature<FILTERED> = "emerging-webapps"
"WORM" then signature<FILTERED> = "emerging-worm"
"TROJAN" then signature<FILTERED> = "emerging-trojan"
"UBIQUITI_CUSTOM" then signature<FILTERED> = "ubiquiti-custom"
"UBIQUITI_RULES" then signature<FILTERED> = "ubiquiti-rules"

```

* * *

# Troubleshooting Detection and Network Interruption

Often times, if there is a service interruption it can be difficult to track down where the problem originates. If detection from Cloudflare and Proofpoint is enabled, who should you contact if you are experiencing a False Positive?

To start your investigation head to the insights tab in the Unifi Webui.

 ![Screenshot 2025-07-17 at 2.54.16 PM](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/2X/6/635a0c0c33692f04bf73b84770180646d51c6fee.png)

There you will see a dropdown for **Blocked or Threats**. All policy hits that are blocked will show up in the **Blocked** page. This is where you will want to focus if you believe CyberSecure is causing a network issue. If you see a dst IP or domain related to your problem, this will identify which Policy Type is taking action.

 ![Screenshot 2025-07-17 at 2.58.44 PM](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/2X/c/cf240c2897718e2937f15bb8e6f41241d5d40836.png)

* * *

# Investigating a Proofpoint / Emerging Threats Detection

To view IPS alerts navigate to `Insights -> Threats`. This displays events triggered by Intrusion Prevention which shows the rule subset responsible for the alert. For example the `Protocol Vulnerabilities` Policy is causing a significant amount of alerts, you could consider disabling that category from the control pane.

 ![Screenshot 2025-07-17 at 3.09.15 PM](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/2X/4/49a5ebfe04ee70485d4c01c4fa150f5d7b6ce00e.png)

If you want to dig deeper into what the rule is detecting, click on the alert for additional details. From here the Signature ID is displayed which can be used to retrieve the full signature text and description from the ruleset.

 ![Screenshot 2025-07-17 at 3.13.22 PM](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/2X/4/42e4a6be1cf9dd1bdeebe2b0963a8dbf8d6a9130.png)

* * *

# Signature Issues? Questions? Let Us Know!

If a signature appears to be generating false positives or causing other issues, reach out to us here or on [Twitter](https://x.com/ET_Labs)! If a signature is causing disruption in your network there is a chance other people are experiencing the same problem.

While we perform quality assurance on every signature we release it’s impossible to anticipate what every network environment looks like. We welcome any and all feedback which helps us provide high quality signatures for the community! Likewise, if you have any questions we are happy to discuss our detection logic.

* * *

# Related Unifi Documentation

- [https://help.ui.com/hc/en-us/articles/25930305913751-UniFi-CyberSecure-by-Proofpoint-and-Cloudflare](https://help.ui.com/hc/en-us/articles/25930305913751-UniFi-CyberSecure-by-Proofpoint-and-Cloudflare)
- [https://help.ui.com/hc/en-us/articles/360006893234-UniFi-Gateway-Intrusion-Detection-and-Prevention-IDS-IPS](https://help.ui.com/hc/en-us/articles/360006893234-UniFi-Gateway-Intrusion-Detection-and-Prevention-IDS-IPS)
