Blog

Find out about the latest from Cloudmersive.

Explore Threat Detection Analytics in the Cloudmersive Management Portal
8/7/2026 - Brian O'Neill


Hero Graphic - Threat Detection Analytics

Threat detection doesn’t end when a risky piece of content is identified. Security teams also need a clear way to get answers: what is being detected? Where is that activity coming from? How are those patterns changing over time?

Cloudmersive Threat Detection Analytics brings that visibility into the Cloudmersive Management Portal. In one comprehensive reporting experience, teams can examine activity across Multi-Threat Detection, Virus Scanning, Content Disarm and Reconstruction (CDR), and Reverse Proxy Server deployments. High-level charts make broader detection trends easy to recognize, while searchable detection records and logs support deeper investigation when it’s needed.

In this tour, we'll walk through all the major groups of Threat Detection Analytics reports and the important questions each group can help answer.

Accessing Threat Detection Analytics

The Management Portal's Analytics page serves as the starting point for all Cloudmersive reporting. Alongside account-wide API analytics and deployment-specific views, the Threat Detection Analytics link opens the security-focused reports covered in this article.

Analytics Page CMP - Safe to Use

The Threat Detection Analytics experience is organized sensibly into related report families. Most reports can be scoped using controls such as API key, endpoint, deployment, time range, granularity, or time zone. This makes it possible to begin with an account-wide view and gradually narrow the report to the activity most relevant to a particular application or environment.

Charts and data views also include practical options for refreshing, copying, downloading, searching, and adjusting the visible data. Rather than requiring teams to work from a single fixed dashboard, the portal supports both quick review and more focused analysis.

Understanding activity across Multi-Threat Detection

Cloudmersive Multi-Threat Detection evaluates content across a variety of complementary security categories. Its analytics reports reflect that broader scope, helping teams understand both overall scanning activity and the types of risks appearing within it.

The Multi-Threat Detections report begins with a time-based view of total scan volume, clean results, threats, and detections. Below that high-level summary, malicious activity is separated into major categories including viruses and malware, phishing, AI-generated content, fraud, spam, and data loss prevention (DLP). Scan errors are also tracked here for transparency.

Multi-Threat Detections 1.

Multi-Threat Detections 2.

This structure allows a security team to recognize a change in overall threat activity without losing sight of what caused it to begin with. For example, a rise in threat detections might be associated with malware, phishing content, sensitive-data exposure, or some other enabled detection layer. The report provides the context needed to distinguish between those detections.

The detection table beneath the chart supports the next level of investigation. Teams can narrow results in several ways, including by threat class, subtype, result, time range, filename, or hash, then review details such as the affected file or object, its source, and the detected threat class. Advanced search, configurable columns, grouping, and export controls make the same data easier to adapt for investigation or reporting workflows.

The companion Multi-Threat Types report summarizes the composition of that activity. Instead of emphasizing when detections occurred, it highlights scan outcomes, threats by class, malware types, common virus names, verified file formats, file-size distribution, detection sources, DLP categories, AI verdicts, and NSFW classifications.

Multi-Threat Types

Together, these two reports answer two different (but closely related) questions: when is threat activity changing, and what kinds of content are driving that change? That distinction helps teams move from broader monitoring into more informed review.

Examining Virus Scan activity and malware patterns

The Virus Scan reports provide a more focused view of malware detections and suspicious file characteristics. They bring together time-based activity, individual detection records, common virus types, scan volume, and the broader classes of content encountered during scanning.

The Virus Scan Detections report charts total threat activity, named viruses, and content threat types over the selected period. The report mirrors Cloudmersive 360-Degree Content Verification capabilities, distinguishing traditional virus detections from potentially dangerous file characteristics such as executables, scripts, macros, embedded objects, invalid files, unsafe archives, password-protected files, and restricted formats.

Virus Scan Detections 1

Virus Scan Detections 2.

Below the chart, the detections table provides a searchable record of individual events (note that this is available on most of the reporting pages, but not all screenshots reflect this). A team can move from a visible change in the timeline to the files, scan types, threats, virus names, and hashes associated with that activity.

The Virus Threat Types report condenses recurring patterns into a set of summary views. These include virus threat types, top virus names, scans by scan type, and detections by API key.

Virus Scan Threat Types

This view is especially useful when the goal is threat comparison rather than threat investigation. It can help reveal whether detections are concentrated around some particular malware family, scanning method, or application represented by a Cloudmersive API key.

For longer-term monitoring, the Virus Detection Volume report charts the number of virus threats detected per selected time unit. Teams can choose the relevant deployment and API key, define the reporting period and interval, and view how detection volume rises or falls across that window.

Virus Detection Volume 1

Virus Detection Volume 2

The resulting timeline makes it easy to see unusual spikes. A sudden increase might warrant investigation into a new upload source, some change in traffic, a targeted campaign, or another event occurring during the same period.

The Virus Threat Classes report complements that timeline with a categorical view. Instead of showing when detections occurred, it simply compares the file and content characteristics found during scanning.

Virus Threat Classes 1

Virus Threat Classes 2

Categories like scripts, executable files, macros, XML external entities, invalid files, password protection, and restricted formats provide a broader picture of the content reaching an environment. These indicators are not all equivalent to a named malware detection, but they can certainly help expose recurring risk patterns, and they can help teams evaluate whether their current handling policies match the content they receive.

Reviewing Content Disarm and Reconstruction results

Content Disarm and Reconstruction takes a slightly different approach to file security. Rather than relying only on a malicious-or-clean decision, CDR processes supported files to remove and/or neutralize potentially dangerous active content while preserving a safe result.

The CDR Detections report visualizes that work over time. It tracks processing outcomes such as files processed, blocked files, and errors, along with the types of content removed and threats disarmed.

CDR Detections

This gives teams a practical view of how often reconstruction is being used and what exactly it’s removing. Activity involving metadata, network content, macros, scripts, executables, embedded objects, XML external entities, insecure deserialization, unsafe archives, and other restricted content can be viewed within the same report.

The CDR Threat Types report presents a more compact summary of CDR operations. Its panels cover threats disarmed, content removed, processing outcomes, file formats, detections by API key, and processing time.

CDR Threat Types

Together, the CDR reports help answer whether files are being reconstructed successfully, which active-content risks appear most often during that process, and whether processing behavior differs across file types or applications. That supports security review and routine service monitoring without forcing teams to inspect every reconstructed file independently.

Moving from trends into detailed logs

Charts are great for identifying patterns, but investigations still require information on the individual events behind them. The Logs report provides that more detailed layer.

Teams can configure this report by deployment type, API key, and result count. An export option and custom search builder support larger reviews or more targeted queries when a general log view is not enough.

Logs 1

The resulting table records the time and type of each event, its scan mode and clean result, and the threat or content indicators associated with it. Depending on the event, this can include found viruses or flags for executables, scripts, macros, password-protected files, restricted formats, unsafe archives, embedded objects, XML external entities, insecure deserialization, and other file characteristics.

Logs 2.

This is where the broader reports become actionable evidence. A team can identify an unusual period or category in a chart, then use the logs to understand which requests and results contributed to it. The goal is not necessarily to read every event manually; rather, it’s to make detailed records available when a pattern needs explanation.

Mapping Reverse Proxy Server threats

For Cloudmersive Reverse Proxy Server deployments, Threat Detection Analytics adds context around the actors and paths involved in hostile activity. Three complementary reports organize that information by threat actor, threat vector, and geographic location.

The Threat Actors report focuses on the IP addresses associated with detected threats for the selected Reverse Proxy Server node.

Threat Actors (Reverse Proxy Server)

The Threat Vectors report, on the other hand, shifts the focus to the specific URLs connected with threat activity. This can help reveal which application paths, resources, or exposed routes are receiving suspicious requests.

Threat Vectors (Reverse Proxy Server)

The Threat Locations report offers a geographic perspective by plotting the origin of threat activity on a simple world map.

Threat Locations (Reverse Proxy Server).

Viewed together, these reports help teams build a more complete picture of activity reaching a protected application: where it came from, which source was involved, and what route it targeted. This context supports investigation, infrastructure review, and decisions about how Reverse Proxy Server protections should be configured.

Turn detection data into operational visibility

Cloudmersive Threat Detection Analytics brings several layers of security reporting into one user-friendly Management Portal experience. Teams can begin with broad activity across Multi-Threat Detection, examine malware-specific patterns, review CDR outcomes, investigate individual events, and map threats observed by Reverse Proxy Server deployments.

The analytics themselves provide visibility rather than enforcement. They show what Cloudmersive security APIs are encountering and how that activity changes, giving teams stronger evidence for policy adjustments, application review, incident response, and ongoing security reporting.

To explore these reports, log in to the Cloudmersive Management Portal and open Analytics, followed by Threat Detection Analytics. For help evaluating Cloudmersive threat detection capabilities for your environment, contact the Cloudmersive team.

600 free API calls/month, with no expiration

Sign Up Now or Sign in with Google    Sign in with Microsoft

Questions? We'll be your guide.

Contact Sales