CrowdStrike Falcon Data Security for Cloud
Compare with…Falcon Data Security for Cloud combines agentless discovery with runtime monitoring of sensitive data flows. Runtime visibility uses eBPF in the Falcon sensor. Request a store-level matrix before treating broad cloud coverage as complete. [1] [2]
Discovery & classification and Detection & response [1]
Sources reviewed 3 sources
Data coverage
Read the scope beside each mark. Support for an environment does not establish every capability in every store.
- Microsoft 365
- Unconfirmed
- AWS
- Partial
The cloud release describes scans of S3, RDS, Redshift and DynamoDB. Runtime protection uses the Linux sensor in EKS and requires Cloud Security for Containers. Confirm current service and edition limits. [3]
- Google Cloud
- Unconfirmed
- Snowflake and Databricks
- Unconfirmed
- On-prem shares
- Unconfirmed
- SaaS apps
- Unconfirmed
Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed
Deployment and cost
How it runs
At-rest discovery and runtime monitoring use different collection paths. [2] [3]
- At rest
- The product page describes agentless cloud scans.
- In motion
- The data sheet describes eBPF monitoring through the Falcon sensor and response workflows through Falcon Fusion SOAR.
- Prerequisite
- The runtime release requires Falcon Cloud Security for Containers. It names EKS and AKS for Linux-sensor deployment.
Pricing and operating workload are not published in the reviewed sources.
Questions for the vendor
- List the exact cloud storage and database engines inspected at rest.
- Which workloads need the Falcon sensor for runtime data-flow visibility?
- Demonstrate the difference between a detection, a SOAR action and an inline block.