Listing Thumbnail

    CrowdStrike Falcon Cloud Security for Red Hat OpenShift Service on AWS

     Info
    Sold by: CrowdStrike 
    Deployed on AWS
    The industry's most complete cloud-native application protection platform (CNAPP) with unified visibility across your apps, clusters, and clouds.
    4.5

    Overview

    CrowdStrike Falcon Cloud Security provides threat detection and response, container vulnerability management, and pre-deployment checks for Red Hat OpenShift Service on AWS (ROSA). Powered by CrowdStrike's leading threat intelligence and AI-native platform, the Falcon sensor stops known, zero-day, and malware-free attacks on OpenShift workloads and the CoreOS operating system.

    Deployed as a Red Hat certified OpenShift operator, the Falcon sensor immediately protects workloads deployed on ROSA from the most advanced adversaries. In addition, application security posture management maps microservice-level security risks; pre-runtime scanning of container images and infrastructure-as-code identifies misconfigurations early; and agentless posture management monitors AWS account usage for indicators of cloud-conscious threat actors.

    Highlights

    • Detect and prevent breaches in applications deployed to ROSA whether they are commercial-off-the-shelf or home-grown by your developers--using over a decade of adversary research and machine learning expertise.
    • Stop misconfigurations from ever being deployed with container image scanning, infrastructure-as-code scanning, and a Kubernetes admission controller.
    • Gain visibility and insights at the microservice-level so developers can minimize risk, and extend protection to the entire AWS estate by monitoring for cloud-conscious adversary activity.

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. Request a private offer to receive a custom quote. Sign in to view any offers that have been extended to you.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    You can log a support ticket for any issues directly from the Falcon Portal or by emailing the support team at cloudmarketplaceoffers@crowdstrike.com  Basic support services such as email communications to the CrowdStrike Support team, access to the support portal and basic troubleshooting and technical assistance.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.5
    161 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    75%
    24%
    1%
    0%
    0%
    0 AWS reviews
    |
    161 external reviews
    External reviews are from G2 .
    Information Technology and Services

    Great application for real time threat detection that is AI driven!

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Crowdstrike doesn’t take up a lot of computer resources the way many security applications do. The real-time AI threat detection helps address issues as soon as they happen, which is reassuring, and it helps to cut down on false positives. I also appreciate having the option to schedule scans, so I can run them at convenient times without interrupting my work.
    What do you dislike about the product?
    I don't have any cons as a user of CrowdStrike Falcon Cloud Security.
    What problems is the product solving and how is that benefiting you?
    It eliminates blind spots and helps reduce multiple alerts, including false positives, thanks to its accurate, AI-driven threat intelligence. This enables faster response times, minimal host performance overhead, and greater confidence that our cloud infrastructure is protected against the latest exploits.
    Trevor Y.

    Easy, Fast Deployment Company-Wide with Intune

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    It was very easy to deploy. I was able to package it and push it out company-wide in Intune in under an hour.
    What do you dislike about the product?
    After the first year of using it, the price jumped significantly, which made it an unsustainable option for my smaller company to keep for multiple years.
    What problems is the product solving and how is that benefiting you?
    It’s been great for securing our servers and end-user devices. It provides a solid dashboard that clearly shows which devices are at risk and which devices are compliant.
    Industrial Automation

    Comprehensive Cloud Security with Excellent Visibility

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about CrowdStrike Falcon Cloud Security is the unified visibility it provides across cloud environments, along with its ability to identify misconfigurations, vulnerabilities, and compliance risks in real time. The platform offers a single pane of glass for monitoring cloud security posture, which makes it easier for both security and engineering teams to prioritize findings and remediate issues quickly. I also appreciate the intuitive dashboard, the actionable insights it surfaces, and the seamless integration with the broader CrowdStrike Falcon platform, all of which help streamline security operations and strengthen overall cloud protection.
    What do you dislike about the product?
    While CrowdStrike Falcon Cloud Security offers strong visibility and comprehensive security coverage, the initial setup and policy tuning can require some learning, especially for teams new to cloud security platforms. The large volume of findings can occasionally feel overwhelming, and it may take time to fine-tune alerts to reduce noise and focus on the highest-priority risks. Additionally, some advanced features have a learning curve and may require more detailed documentation or training to fully leverage.
    What problems is the product solving and how is that benefiting you?
    CrowdStrike Falcon Cloud Security helps us address cloud misconfigurations, vulnerabilities, compliance gaps, and security risks across our multi-cloud environment. It provides centralized visibility into cloud assets and continuously monitors for potential threats, enabling our team to identify and remediate issues much faster than with manual processes. As a result, we've improved our security posture, reduced risk exposure, streamlined compliance efforts, and saved valuable engineering and security team time through automated detection and prioritization of critical findings.
    Aswindev P.

    Real-Time Cloud Protection with eBPF and Unified Telemetry

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    If you ask me to strip away the marketing fluff and look purely at the architectural reality, the absolute biggest upside of CrowdStrike Falcon Cloud Security is its hybrid convergence of agentless visibility and real-time runtime enforcement.

    ​For the last few years, the industry was obsessed with pure "agentless" tools. But when you are engineering complex, multi-cloud architectures across AWS, Azure, and GCP, relying purely on API snapshots is a massive blind spot. An API scan running every 15 minutes will tell you that an S3 bucket is exposed, but it will absolutely miss a threat actor dropping a fileless malware payload into the memory of a running EC2 instance.

    ​Here is what is actually helpful about CrowdStrike's approach in the trenches:

    ​1. Real-Time Kill Capabilities via eBPF

    ​This is the platform's architectural crown jewel. Instead of relying on clunky legacy kernel modules that crash production servers, CrowdStrike utilizes an eBPF (Extended Berkeley Packet Filter) sensor for its Cloud Workload Protection (CWPP). eBPF sits safely within the Linux kernel, acting as an ultra-lightweight observer.

    If an attacker exploits a vulnerability in a containerized web app and attempts to spawn a malicious reverse shell, pure agentless tools will just log it after the fact. CrowdStrike's eBPF sensor intercepts the system call and strictly kills the process in milliseconds, all without disrupting the underlying host. It provides the surgical precision required to stop an active breach without bringing down production infrastructure.

    ​2. Frictionless Integration with Infrastructure as Code (IaC)

    ​Security tools that require manual deployment are dead on arrival in modern cloud environments. The Falcon sensor is designed to be completely invisible to developers. It deploys natively via DaemonSets in Kubernetes clusters or bakes seamlessly into Terraform and Ansible provisioning workflows. Because it doesn't conflict with custom Python, Bash, or PowerShell automation scripts running on the host, infrastructure engineering teams can build secure-by-default cloud environments without security becoming a deployment bottleneck.

    ​3. Identity and Entitlement Mapping (CIEM)

    ​In the cloud, identity is the new network perimeter. The most common way cloud environments get breached isn't through zero-day exploits; it is through over-provisioned IAM roles. CrowdStrike excels at Cloud Infrastructure Entitlement Management (CIEM). It constantly graphs out exactly which machine identities, service accounts, and human users have access to which cloud resources. If an EC2 instance in AWS has an attached IAM role that secretly allows it to dump an entire DynamoDB database, the platform flags that toxic combination before an attacker can leverage it for lateral movement.

    ​4. Consolidated Telemetry (The Single Agent Advantage)

    ​If an enterprise is already running CrowdStrike Falcon on its corporate laptops, extending that exact same telemetry engine into the cloud control plane is a massive operational win. Instead of forcing a SOC analyst to pivot between a cloud posture tool, a container vulnerability scanner, and an endpoint EDR console, it all feeds into a single unified threat graph. You can trace an attack path from a compromised developer laptop straight through to a misconfigured Azure Kubernetes Service (AKS) cluster in one seamless workflow.

    ​Ultimately, the best thing about Falcon Cloud Security is that it doesn't just hand you a massive Excel spreadsheet of cloud misconfigurations; it actually possesses the execution power to stop the resulting attacks in real-time.
    What do you dislike about the product?
    If I take off the vendor marketing glasses, the reality is that managing CrowdStrike Falcon Cloud Security at an enterprise scale comes with significant operational friction and a notoriously steep price tag.

    ​While the platform is incredibly powerful, here are the biggest architectural and operational downsides you will fight in the field:

    ​1. The "Single Agent" Blast Radius (The 2024 Hangover)

    ​The biggest architectural selling point having one unified sensor for everything is also its biggest systemic risk. The massive global IT outage in July 2024 permanently shifted how architects view CrowdStrike. When you deploy an agent into your cloud workloads, you are granting a third-party vendor the ability to push dynamic content updates directly into the execution path of your mission-critical applications. If a kernel-level update goes sideways, it doesn't just break an employee's laptop; it can take down your revenue-generating AWS or Azure production clusters. To survive, cloud engineers are now forced to spend significant time building complex "N-1" or "N-2" staggered update rings just to protect their infrastructure from their own security tool.

    ​2. Kernel Compatibility and The "Agent Lifecycle" Tax

    ​CrowdStrike markets their sensor as frictionless, but managing software agents across tens of thousands of ephemeral, auto-scaling cloud workloads is inherently painful. While their eBPF architecture is modern, you are still permanently chained to CrowdStrike's supported OS and kernel matrix. If your DevOps team wants to upgrade a Kubernetes node pool to a cutting-edge Linux kernel, they have to wait for CrowdStrike to officially support it. If they upgrade prematurely, the sensor breaks or falls back to a degraded user-space mode, creating immediate blind spots in your cloud posture.

    ​3. Module Sprawl and Licensing Shock

    ​CrowdStrike's pricing model is aggressively modular. You do not just buy "Cloud Security." You buy the base Cloud Workload Protection (CWP) for the sensor. Then you realize you need Cloud Security Posture Management (CSPM) to scan APIs. Then you need separate entitlements for container image scanning, identity management (CIEM), and Data Security Posture (DSPM). IT leadership frequently experiences severe "renewal shock" when they realize the true Total Cost of Ownership (TCO) required to unlock the platform's full capabilities, making it a very tough sell for organizations without massive security budgets.

    ​4. The "Acquisition Frankenstein" Console

    ​CrowdStrike built much of its advanced cloud pipeline through rapid acquisitions (like Reposify for attack surface, Bionic for application security, and Flow Security for data posture). While they integrate these tools better than most legacy vendors, the Falcon console has become incredibly dense and complex. For a smaller SOC team or a cloud engineer just trying to figure out why a specific container build failed, navigating the interface can feel overwhelming. It often suffers from information overload, making it difficult to separate high-priority runtime alerts from low-level cloud misconfiguration noise.

    ​Ultimately, the downside isn't that the tool fails to secure the environment; it is that maintaining it requires a highly mature engineering culture and a massive budget.
    What problems is the product solving and how is that benefiting you?
    The fundamental business problem CrowdStrike Falcon Cloud Security solves is the massive visibility and execution gap between traditional IT security and agile cloud DevOps.

    ​In the trenches of large-scale consulting engagements especially when architecting complex, multi-cloud transformations across AWS, Azure, and GCP for enterprise clients out of hubs like KPMG India security teams are consistently outpaced by developers. Infrastructure teams can spin up vulnerable containers or provision wildly over-permissioned IAM roles in minutes, and legacy security tools simply cannot keep up.

    ​Here are the core business problems I use CrowdStrike to solve, and the direct benefits to the enterprise:

    ​1. Solving the "Siloed Telemetry" Crisis

    ​The Problem: Most organizations run a highly fragmented stack. They use native cloud tools (like AWS GuardDuty), a separate container scanner, and completely different endpoint protection platforms. This forces security analysts to manually stitch together disconnected logs just to figure out if a threat is real.

    The Benefit: CrowdStrike consolidates this telemetry. It tracks the entire attack path natively. If a compromised credential on a corporate laptop is used to pivot into a production Azure environment, I can see that exact sequence in one unified threat graph. This drastically reduces the Mean Time to Respond (MTTR) because the SOC isn't wasting hours correlating logs. Furthermore, I can seamlessly feed this high-fidelity cloud intelligence into parallel endpoint platforms like Tanium or Microsoft Defender to lock down the broader enterprise posture instantly.

    ​2. Eliminating Security as a DevOps Bottleneck

    ​The Problem: Traditional security agents require manual installation, crash production servers, and frequently break custom automation. This forces security teams to act as gatekeepers, which severely slows down revenue-generating product releases.

    The Benefit: By leveraging Python, PowerShell, and Bash scripting, infrastructure engineers can fully automate the deployment of CrowdStrike's lightweight eBPF sensors directly into their CI/CD pipelines, Kubernetes DaemonSets, or Terraform code. Security becomes entirely invisible to the developer. The business benefits by maintaining rapid, agile release cycles without sacrificing runtime protection.

    ​3. Bridging the Cloud Entitlement Gap (CIEM & CSPM)

    ​The Problem: A single misconfigured S3 bucket or a dormant, over-privileged IAM role can lead to a multi-million dollar data breach. Auditing thousands of ephemeral cloud resources manually is mathematically impossible.

    The Benefit: CrowdStrike continuously scans the cloud control plane via APIs to catch these configuration drifts in real-time. It maps out exactly which machine identities and service accounts have access to what data. This proactive enforcement prevents breaches before an attacker can exploit the misconfiguration, simplifying the pain of strict ITGC compliance audits and significantly reducing the organization's cyber insurance liability.

    ​Ultimately, I deploy CrowdStrike to allow the business to adopt cloud-native architectures aggressively, without accidentally leaving the front door wide open.
    Sumit K.

    Agentless Cloud Scanning That Quickly Catches Misconfigurations and Runtime Threats

    Reviewed on Jul 26, 2026
    Review provided by G2
    What do you like best about the product?
    The agentless scanning across our cloud accounts flagged a misconfigured storage bucket within hours of setup, something our manual audits had missed for weeks. Seeing runtime threats and misconfigurations in the same dashboard means our security team isn't switching tools to piece together whats actually going on.
    What do you dislike about the product?
    The initial onboarding across multiple cloud accounts took longer than we expected, mostly around getting the IAM permissions set up correctly on our end.
    What problems is the product solving and how is that benefiting you?
    It gave our small security team visibility we did not have before across AWS and Azure without needing separate tools for posture management and runtime protection. The onboarding took some patience, but once it was running, it caught issues our previous manual checks kept missing.
    View all reviews