Analyze F5 Agentic Threat Intelligence
Objective
F5 Agentic Threat Intelligence is a new capability built on technology integrated into the F5 Console, Application Delivery and Security Platform (ADSP), starting with F5 Distributed Cloud WAF.
Using agentic AI to autonomously correlate external threat intelligence with your internal WAF data. Surfacing high-impact threats, delivering prioritized, actionable recommendations, also simultaneously reducing alert fatigue and accelerating response.
Overview
AI that doesn't just process data, but takes proactive action-analyzing, correlating, prioritizing, and recommending tasks autonomously.
Agentic AI: AI that takes proactive action-correlating, prioritizing, and recommending tasks autonomously.
OSINT (Open Source Intelligence): Process of collecting and analyzing publicly available information to assess threats, inform decisions, and answer security questions.
CVE Correlation: Matching CVEs identified in external threat intel with CVEs linked to WAF signature matches in your environment.
Prerequisites
-
F5® Distributed Cloud Services Account. If you do not have an account, see Getting Started with Console.
-
An HTTP/HTTPS load balancer in your edge/cloud site, or in the F5 global network cloud. If you do not have a load balancer, see HTTP Load Balancer for instructions to create one.
Configuration
Security analysts can run discovery on possible applications and objects to block now with agentic threat intelligence in security load balancer feature.
You can view all possible threats and act on outcomes F5 agentic threat intelligence provides with specific applications and addresses to protect your apps.
Perform the following to discover F5 agentic threat intelligence outcomes:
Step 1: Open F5 Console, Web App & API Security.
-
Open Web App & API Security.
-
Select Security in Overview section.
Step 2: Open Load Balancer Security Analytics.
- Select Load Balancer Name in Dashboard.
Note: Load balancer at bottom of dashboard, scroll to find.
- Select Security Analytics tab option.
Step 3: Open and Analyze Threat Intelligence.
-
Select Events tab.
-
Select Event Time to open Event Details.
-
In Event Details pop-up, select Information.
Note: Review Attack Signatures etc. to see if they match a CVE threat.
-
Select Agentic Threat Intelligence.
-
Review Summary, Severity, CVEs on each Attack to discover potential risks.
-
Review Overview, IoCs (Indicators of Compromise), and Advice tabs to view more information.
Note: Use this discovery to match hashes, IoCs, logs, applications to block threat in F5 console.
Step 4: Discover and Assess Threat Intelligence Results.
Use discovery to match hashes, IOCs, logs, applications, etc to block threat in F5 console.
Trend the Threat Landscape: The system continuously scans the open web and specialized cyber sources, including OSINT (Open Source Intelligence), to identify trending and emerging threats.
Correlate Threats to CVEs: External threats are mapped to the specific CVEs being actively exploited.
Autonomously Correlate: The AI correlates internal WAF signature and CVE data with external threat intelligence with no manual effort required.
Note: Distributed Cloud WAF signatures are frequently linked to one or more CVEs.
Generate High-Impact Threat List: Surfaces threats that are real, relevant, and urgent to your environment.
Transform Threats into Tasks with Context: Converts findings into clear, actionable tasks, and recommendations that offer both:
-
Short-Term Actions: Block malicious IPs and apply virtual patches.
-
Long-Term Guidance: Policy adjustments and remediation strategies.