---
title: "Threat defense"
description: "Detect, analyze, and block threats in your Calico Enterprise cluster with intrusion detection, threat intelligence feeds, deep packet inspection, and a workload-based WAF."
product: "Calico Enterprise"
version: "3.23 (latest)"
section: "Threat defense"
canonical_url: "https://docs.tigera.io/calico-enterprise/latest/threat/"
---

# Threat defense

Use real-time monitoring to detect and block threats to your cluster.

##### [Security event management](https://docs.tigera.io/calico-enterprise/latest/threat/security-event-management.md)

[Triage and manage security events from your Calico Enterprise cluster in the Security Events Dashboard, with filtering, exceptions, and recommended remediation.](https://docs.tigera.io/calico-enterprise/latest/threat/security-event-management.md)

##### [Trace and alert on suspicious domains](https://docs.tigera.io/calico-enterprise/latest/threat/suspicious-domains.md)

[Add threat intelligence feeds to Calico Enterprise to detect DNS queries to suspicious domains and surface impacted pods in the anomaly dashboard.](https://docs.tigera.io/calico-enterprise/latest/threat/suspicious-domains.md)

##### [Trace and block suspicious IPs](https://docs.tigera.io/calico-enterprise/latest/threat/suspicious-ips.md)

[Add threat intelligence feeds to Calico Enterprise to alert on flows to suspicious IP addresses and optionally block them with a dynamic deny-list policy.](https://docs.tigera.io/calico-enterprise/latest/threat/suspicious-ips.md)

##### [Workload-based Web Application Firewall (WAF)](https://docs.tigera.io/calico-enterprise/latest/threat/web-application-firewall.md)

[Protect cluster workloads from Layer 7 attacks with the Calico Enterprise workload-based WAF, powered by Envoy sidecars and the OWASP ModSecurity Core Rule Set.](https://docs.tigera.io/calico-enterprise/latest/threat/web-application-firewall.md)

##### [Webhooks for security events](https://docs.tigera.io/calico-enterprise/latest/threat/configuring-webhooks.md)

[Configure Calico Enterprise webhooks to post security event alerts to Slack, Jira, Alertmanager, or generic JSON endpoints from your self-hosted cluster.](https://docs.tigera.io/calico-enterprise/latest/threat/configuring-webhooks.md)

##### [Deep packet inspection](https://docs.tigera.io/calico-enterprise/latest/threat/deeppacketinspection.md)

[Run deep packet inspection on selected workloads in your Calico Enterprise cluster with Snort community rules to alert on suspected malicious traffic.](https://docs.tigera.io/calico-enterprise/latest/threat/deeppacketinspection.md)

##### [Anonymization attacks](https://docs.tigera.io/calico-enterprise/latest/threat/tor-vpn-feed-and-dashboard.md)

[Detect anonymization activity in your Calico Enterprise cluster with Tor bulk exit and X4B VPN feeds, and investigate findings in the Tor-VPN Kibana dashboard.](https://docs.tigera.io/calico-enterprise/latest/threat/tor-vpn-feed-and-dashboard.md)
