Skip to content
ThreatSTOP for AWS Blog

Extend CrowdStrike protection to every device on your network.

Endpoint protection only covers devices that can run an agent, and attackers know exactly which of your devices cannot. ThreatSTOP takes CrowdStrike's threat intelligence and enforces it at the network layer, so the printers, cameras, servers, and IoT devices Falcon cannot reach are protected too.

Take predictive security to the next level.

The threat landscape changes fast, but the joint ThreatSTOP and CrowdStrike solution moves faster, because it is automated. New and emerging indicators discovered by CrowdStrike can be added to firewall and DNS rules at machine speed. CrowdStrike integrates threat intelligence into endpoint protection; ThreatSTOP integrates that same intelligence into network protection.

01
CrowdStrike finds the threat
Falcon Intelligence delivers comprehensive, actionable indicators of compromise, and delivers tailored indicators automatically to ThreatSTOP.
02
ThreatSTOP turns it into policy
The ThreatSTOP Platform receives continuous indicator updates from the Falcon Platform and transforms them into dynamic enforcement policies.
03
Your network enforces it
ThreatSTOP delivers continuously updated policies containing Falcon Intelligence indicators directly to your firewalls, routers, DNS servers, and more.

Protect everything.

Coverage
Protect what an agent cannot reach
Network-layer protection for clients that are not compatible with the Falcon sensor, including IoT devices, servers, and databases.
Enforcement
Block, do not just alert
Threats should be blocked, not just alerted on. CrowdStrike's intelligence gets dropped at the network edge, before a connection completes.
Deployment
Deploy over lunch
Deployment takes about an hour with no heavy lifting, and the security results are immediate. Broadly compatible with leading NGFW, router, switch, IDS/IPS, DDI/IPAM, and DNS servers.

Operationalize threat intelligence.

The challenge

Anticipating and preventing attacks before they happen, by proactively blocking communication with high-confidence indicators of compromise, yields significant security results. Doing that by hand does not scale.

The solution

Automation that accomplishes real-time operationalized threat intelligence, in a fully cloud-delivered integration between CrowdStrike and ThreatSTOP.

What the customer gets

By automating real-time updates to network traffic policy using actionable indicators from CrowdStrike, your network stops communicating with threat actors, and breach protection extends to every device on the network rather than only the ones running an agent.

Put your CrowdStrike intelligence to work.

See what the joint solution blocks on your own network. Setup takes about an hour.