
2/27/2026 · Bashyam Anant, Himanshu Anand
What this post added
This post introduces the concept of 'toxic combinations' as a method for detecting security incidents by analyzing the confluence of multiple weak signals rather than relying on single strong indicators. It details how Cloudflare's network observes requests to identify these combinations by looking at bot traffic, application paths, request anomalies, and misconfigurations. The post provides examples of common toxic combinations, such as probing administrative endpoints and unauthenticated API endpoints with predictable identifiers, and offers mitigation strategies for each.