CrowdStrike Introduces Adversary-Focused CNAPP Capabilities Designed to Secure and Protect Cloud Applications from Sophisticated Threats
CrowdStrike (NASDAQ: CRWD) has enhanced its Falcon platform by introducing new capabilities for its Cloud Native Application Protection Platform (CNAPP). These updates aim to boost threat hunting and reduce response times in cloud environments, integrating features from Falcon Horizon and Falcon Cloud Workload Protection (CWP). Key improvements include a centralized console, automated remediation workflows for AWS, and enhanced security measures for Azure and Google Cloud. The adversary-focused approach provides comprehensive visibility and can help organizations secure their multi-cloud infrastructures. The new features will be available to customers in May.
- Enhanced CNAPP capabilities to improve cloud security and threat hunting.
- Integration of Falcon Horizon and Falcon CWP for better user experience.
- Automated remediation workflows for AWS, increasing operational efficiency.
- New identity access analyzer for Azure enhances security against threats.
- Custom Indicators of Misconfigurations for GCP to align security with business goals.
- Agent-based and agentless security options provide organizations flexibility.
- None.
Falcon platform offers cloud security with agent-based and agentless protection, which provides organizations the flexibility they need to secure their cloud environments
CrowdStrike’s adversary-focused approach to CNAPP provides both agent-based (Falcon CWP) and agentless (Falcon Horizon) solutions delivered from the Falcon platform. This gives organizations the flexibility necessary to determine how best to secure their cloud applications across the continuous integration/continuous delivery (CI/CD) pipeline and cloud infrastructure across AWS, Azure and GCP. The added benefit of an agent-based CWP solution is that it enables pre-runtime and runtime protection, compared to agentless-only solutions that only offer partial visibility and lack remediation capabilities.
“What sets
CrowdStrike’s adversary-focused CNAPP capabilities include:
New centralized console for Falcon Horizon and Falcon CWP
- Cloud activity dashboard. Unify CSPM insights from Falcon Horizon with workload protection from Falcon CWP into a single user experience to prioritize top issues, address runtime threats and enable cloud threat hunting, resulting in faster investigation and response.
New capabilities for Falcon Horizon
- Automated remediation workflow for AWS. Respond to threats with guided and automated remediations powered by Falcon Fusion. Workflows give context and prescriptive guidance needed to fix issues and reduce time to resolve incidents.
- Identity access analyzer for Azure. Prevent identity-based threats and ensure Azure AD groups, users and apps have permissions enforced based on least privilege. This capability extends Falcon Horizon’s existing identity access analyzer functionality for AWS.
- Custom Indicators of Misconfigurations (IOMs) for GCP. Ensure security is part of every cloud deployment with custom policies that align with business goals. This capability extends Falcon Horizon’s existing custom IOM functionality for AWS and Azure.
New capabilities for Falcon CWP
- Falcon container detection. Defend against malware and sophisticated threats targeting containers automatically with machine learning (ML), artificial intelligence (AI), indicators of attack (IOAs), deep kernel visibility and custom indicators of compromise (IOCs) and behavioral blocking.
- Rogue container detection. Maintain an up-to-date inventory as containers are deployed and decommissioned. Additionally, scan rogue images and identify and stop containers launched as privileged or writable – which can be used as entry points for attacks.
- Drift container prevention. Discover new binaries created or modified at runtime to protect the immutability of the container.
“One of the big benefits I've witnessed is that
“We’re blown away by the performance of
“CrowdStrike’s ability to provide an adversarial perspective on cloud attack chains supports the strategic imperative for organizations to update their threat model to include their cloud footprint,” said
All CNAPP capabilities will be generally available for customers in May.
Additional Resources
- For more information on CrowdStrike’s adversary-focused CNAPP approach, please visit our blog.
-
CrowdStrike was recently named a Strong Performer in The Forrester WaveTM: Cloud Workload Security, Q1 2022 report.1
About
Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities.
Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity and immediate time-to-value.
Learn more: https://www.crowdstrike.com/
Follow us: Blog | Twitter | LinkedIn | Facebook | Instagram
Start a free trial today: https://www.crowdstrike.com/free-trial-guide/
© 2022
1 The Forrester Wave™: Cloud Workload Security, Q1 2022
View source version on businesswire.com: https://www.businesswire.com/news/home/20220427005358/en/
press@crowdstrike.com
Source:
FAQ
What are the new capabilities introduced by CrowdStrike for its CNAPP in 2023?
When will the new CNAPP features from CrowdStrike be available?
How does CrowdStrike's CNAPP handle threats in multi-cloud environments?
What is the significance of the centralized cloud activity dashboard in CrowdStrike's CNAPP?