Listing Thumbnail

    CloudFence Agentless Network & Identity Security

     Info
    Sold by: CloudFence 
    CloudFence Monitors your cloud network like an invisible overhead drone. It studies the normal patterns of how workloads and non-human identities behave - who they talk to, where they send data, what access they actually use, and immediately alerts the moment one starts behaving in an unfamiliar way, thus blocking suspicious activities before they escalate into attacks. CloudFence then uses the learned behavior to help you scope down your wide open and unused IAM and Security Group access to what's actually needed, without the risk of blocking legitimate access and causing an incident.

    Overview

    CloudFence is an agentless behavioral cloud security platform for AWS and Azure. It monitors your cloud network like an invisible overhead drone, studying the normal patterns of how workloads and non-human identities behave: who they talk to, where they send data, and what access they actually use. The moment one starts behaving in an unfamiliar way, CloudFence alerts you, so suspicious activity is caught before it escalates into an attack. CloudFence is built for cloud security and devops engineers responsible for production environments that hold regulated data or run AI and agentic workloads. An AI agent is a non-human identity with network access, and its behavior is the most reliable signal of what it is actually doing. CloudFence is read-only and agentless. It uses logs your cloud accounts already produce, so there is nothing to install on your workloads and no traffic to reroute. With CloudFence, organizations gain: Behavior baselining across the network and identity layers. For every workload, CloudFence learns the full traffic pattern: the ports it communicates on inbound and outbound, and what it talks to, whether that is a domain, a country, another VPC, or another workload. For every role, service account, and access key, it learns who normally uses the identity and from where, which actions they perform, and on which resources. Suspicious activity outside the learned patterns surfaces as an alert. Egress traffic control and DNS visibility. See every domain, destination, and country your workloads reach, with the volume moved and which workload moved it. Get alerted when a workload sends data somewhere it never has, contacts a domain with a known bad reputation or one registered days ago, or reaches a country outside your compliance scope. A live map of your environment with traffic flows. What talks to what across VPCs, regions, and accounts, including what enters and leaves each VPC. This is how you catch paths that should not exist: staging reaching into production, internal applications talking to each other through a public load balancer IP, or S3 traffic routed through a NAT gateway instead of a VPC endpoint. Least privilege for non-human identities. CloudFence tracks which permissions your roles, and access keys actually use, and which ones have never been touched. You get a recommended policy built from real activity, so you can remove unused access and cut over-permissioned identities down to what they need without breaking anything. Security group hardening. CloudFence compares what each rule allows against the traffic it actually carries, with hit counts and last seen activity per rule. You get the unused rules, the redundant ones, and the wide open ranges narrowed to the IPs and ports in real use, so you can shrink your attack surface without risking an outage.

    Highlights

    • Egress Traffic Control. CloudFence learns the outbound pattern of every workload: which domains it talks to, which countries it reaches, how much data it sends. It alerts the moment a workload steps outside that pattern, sending data somewhere it never has, contacting a domain with a bad reputation or one registered days ago, or reaching a country outside your compliance scope.
    • A live map of your environment with traffic flows. See what talks to what, across VPCs, regions, and accounts, including inbound, outbound, and east-west traffic. Identify unexpected paths that should not exist such as staging vpc talking to production, one application calling another through a public load balancer IP instead of staying internal, or data going to S3 through a NAT gateway instead of a VPC endpoint.
    • Least privileges. CloudFence compares what your environment grants against what it actually uses, on both the network and identity side. For Security groups CloudFence compares what each rule allows against the traffic it actually carries, with hit counts and last seen activity per rule. You get the unused rules, the redundant ones, and the wide open ranges narrowed to the IPs and ports in real use, so you can shrink your attack surface without risking an outage.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    CloudFence Agentless Network & Identity Security

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    CloudFence - Agentless Cloud Network Security
    Full CloudFence platform for your cloud environments ingesting up to 100 GB of vpc flow logs per day. Includes egress and DNS visibility, network map, behavioral deviation detection across network and identity, security group hardening, and IAM least-privilege analysis.
    $50,000.00

    Vendor refund policy

    Contact our support team for refund information.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.