CloudFence provides a network management platform that continuously monitors cloud workload communications and identity activities, establishing behavioral baselines to detect and prevent suspicious activities. By automatically removing unused access and restricting network permissions, the platform enhances cloud security and visibility, mitigating the risk of lateral movement by attackers.
Funding
Funding not disclosed
Founders
Product
Problem
Many cloud workloads have overly permissive network access, especially outbound, creating opportunities for attackers to move laterally within the cloud environment. Security and DevOps teams lack a unified platform to visualize cloud architecture, monitor workload communications, and identify unused or excessive permissions. Existing cloud network logs are often not correlated with cloud context, hindering effective threat detection and response.
Solution
CloudFence provides a network management platform that continuously monitors cloud workload communications and identity activities to establish behavioral baselines and detect suspicious activities. The platform correlates network logs with cloud context, providing security and DevOps teams with actionable insights. By automatically identifying and removing unused access and restricting network permissions, CloudFence hardens the cloud environment and reduces the attack surface. This proactive approach enhances cloud security and visibility, mitigating the risk of lateral movement and preventing attacks from escalating.
Target Audience
CloudFence is designed for security and DevOps teams responsible for managing and securing cloud environments, particularly those seeking to improve visibility, reduce the attack surface, and prevent lateral movement by attackers.
Features
- Continuous monitoring of network communications and identity activities for cloud workloads.
- Automatic correlation of VPC flow logs and DNS logs with cloud context.
- Behavioral baselining to identify deviations and suspicious activities.
- Automated detection and removal of unused network access and identity permissions.
- Real-time visualization of cloud architecture, including inbound, outbound, and DNS communications.
- Cross-checking of network communications against security group configurations.