I see lots of UNCLASSIFIED threats in Analytics. This question was asked last month and it got
no responses. Can Cloudflare Support Team explain what these Unclassified Threats mean?
What can we do to mitigate these threats or safeguard our sites from any hard that these threats
may cause. Some explanation will be most appreciated. Thank you.
These are not massive threats. In case of blocks caused by known IP reputation or WAF rules, you should be able to find this information in the IP Firewall. The Unclassified threat type comprises a number of automatic blocks that are not related to the Browser Integrity Challenge (Bad Browser).
These threats are usually related with Hotlink Protection, and other actions that happen on the Edge based on the composition of the request (and not its content). Unclassified means a number of conditions which we groups common threats related to Hotlink protection, certain cases of IP reputation and specific requests that are blocked at the Cloudflare edge before reaching your servers.
Thanks. That document was the first place I checked, but it did not mention “Unclassified.” It makes sense that all the other random blocks fall under this category.