Skip to content

Latest commit

 

History

History
46 lines (26 loc) · 2.83 KB

File metadata and controls

46 lines (26 loc) · 2.83 KB

Container Runtime Defense

Container Runtime Protection Against Active Threats And Policy Violations

Twistlock runtime defense protects your containers against exploits, compromises, application flaws and configuration errors. We monitor container activities, detect policy violations, report anomalies, and execute corrective actions. We do all this without changing your host, your container daemon, or your applications.

Smart Policies

Twistlock runtime protection for containers uses a set of automatic profiling policies to detect anomalies in runtime. These policies are derived from system call profiling, malicious behavior fingerprinting, user access analysis, and intelligence from image scanning during development. These policies require little to zero intervention from sysadmins and are a powerful tool to detect active threats and compromises.

Config/Process Management

Our runtime protection solution provides easy-to-use policy templates, including best practices from the CIS benchmark, and a policy interface to specify approved settings, certified images and sanctioned processes for production containers. Twistlock defenders can enforce policies (e.g., no root, no SSH enabled), detect violations, and execute remediation for every container in your environment.

Network Activity Profiling

We can automatically build network activity profiles for containers, detect deviating behavior dynamically, spot suspicious communications to compromised IP’s, and report policy-violating network actions. We can also enforce container linkages and port restrictions. When policy violations occur, we can notify, log, block user access, or kill compromised containers.

Visibility & Analytics

Twistlock's console provides a central dashboard displaying the number of active containers, vulnerability information, software libraries used, risk visualization/trending, policy violations, corrective actions, and user activities. Twistlock logs everything in native syslog format for easy SIEM integration and analytics.

Dev-to-Production Vantage Point

For DevOps, policies governing static container images are often the same policies applied to running containers. Twistlock can enforce consistent policies from dev time to production with our container tagging framework and central intelligence. Our unique vantage point in both dev and production enables us to optimally gather intelligence and enforce policies for your production applications.

Real-time Threat Intelligence

The Twistlock Intelligence Stream includes real-time threat feeds from a variety of sources covering known malicious sites, command & control servers, high risk IP ranges and attack signatures. Twistlock defenders use this information to detect compromised containers and the existence of active threats.