---
title: "Threat defense"
description: "Trace, analyze, and block malicious threats using intelligent feeds and alerts."
product: "Calico Enterprise"
version: "3.21"
section: "Threat defense"
canonical_url: "https://docs.tigera.io/calico-enterprise/3.21/threat/"
---

# Threat defense

Use real-time monitoring to detect and block threats to your cluster.

##### [Security event management](https://docs.tigera.io/calico-enterprise/3.21/threat/security-event-management.md)

[Manage security events from your cluster in a single place.](https://docs.tigera.io/calico-enterprise/3.21/threat/security-event-management.md)

##### [Trace and alert on suspicious domains](https://docs.tigera.io/calico-enterprise/3.21/threat/suspicious-domains.md)

[Add threat intelligence feeds to trace DNS queries that involve suspicious domains.](https://docs.tigera.io/calico-enterprise/3.21/threat/suspicious-domains.md)

##### [Trace and block suspicious IPs](https://docs.tigera.io/calico-enterprise/3.21/threat/suspicious-ips.md)

[Add threat intelligence feeds to trace network flows of suspicious IP addresses, and optionally block traffic to them.](https://docs.tigera.io/calico-enterprise/3.21/threat/suspicious-ips.md)

##### [Workload-based Web Application Firewall (WAF)](https://docs.tigera.io/calico-enterprise/3.21/threat/web-application-firewall.md)

[Configure Calico to use with Layer 7 Web Application Firewall.](https://docs.tigera.io/calico-enterprise/3.21/threat/web-application-firewall.md)

##### [Webhooks for security events](https://docs.tigera.io/calico-enterprise/3.21/threat/configuring-webhooks.md)

[Use webhooks to send security event alerts to third-party systems.](https://docs.tigera.io/calico-enterprise/3.21/threat/configuring-webhooks.md)

##### [Deep packet inspection](https://docs.tigera.io/calico-enterprise/3.21/threat/deeppacketinspection.md)

[Monitor live traffic for malicious activities.](https://docs.tigera.io/calico-enterprise/3.21/threat/deeppacketinspection.md)

##### [Anonymization attacks](https://docs.tigera.io/calico-enterprise/3.21/threat/tor-vpn-feed-and-dashboard.md)

[Detect and analyze malicious anonymization activity using Tor-VPN feeds.](https://docs.tigera.io/calico-enterprise/3.21/threat/tor-vpn-feed-and-dashboard.md)
