Data Security Platforms
Research preview. Based on public sources, not deployment testing.
← All platforms

CrowdStrike Falcon Data Security for Cloud

Compare with…

Falcon Data Security for Cloud combines agentless discovery with runtime monitoring of sensitive data flows. Runtime visibility uses eBPF in the Falcon sensor. Request a store-level matrix before treating broad cloud coverage as complete. [1] [2]

Capabilities

Discovery & classification and Detection & response [1]

Sources reviewed 3 sources

Data coverage

Read the scope beside each mark. Support for an environment does not establish every capability in every store.

Microsoft 365
Unconfirmed
AWS
Partial

The cloud release describes scans of S3, RDS, Redshift and DynamoDB. Runtime protection uses the Linux sensor in EKS and requires Cloud Security for Containers. Confirm current service and edition limits. [3]

Google Cloud
Unconfirmed
Snowflake and Databricks
Unconfirmed
On-prem shares
Unconfirmed
SaaS apps
Unconfirmed

Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed

Deployment and cost

How it runs

At-rest discovery and runtime monitoring use different collection paths. [2] [3]

At rest
The product page describes agentless cloud scans.
In motion
The data sheet describes eBPF monitoring through the Falcon sensor and response workflows through Falcon Fusion SOAR.
Prerequisite
The runtime release requires Falcon Cloud Security for Containers. It names EKS and AKS for Linux-sensor deployment.

Pricing and operating workload are not published in the reviewed sources.

Questions for the vendor

  1. List the exact cloud storage and database engines inspected at rest.
  2. Which workloads need the Falcon sensor for runtime data-flow visibility?
  3. Demonstrate the difference between a detection, a SOAR action and an inline block.

Sources

  1. crowdstrike.com
  2. crowdstrike.com
  3. crowdstrike.com