5 Ways You Can Use Deception in a Mythos-like AI Era

Fidelis Container Secure™

Secure Every Layer of Your Container Stack

Automates cloud container security across the entire infrastructure stack, from registries and images to runtimes, Kubernetes, and DevOps toolchains.

Containers Move Fast. Attackers Move Faster.

Traditional security tools were not designed to protect containerized environments. Fidelis Container Secure™ was built from the ground up to secure every layer of the container stack without becoming a bottleneck to rapid application development and deployment.

 Accredited By the Best in Business

30 Fastest growing companies
CRN
Lyell
Enterprise Security

Fidelis Container Secure
Agile. Comprehensive. Automated.

Fidelis Container Secure™ integrates and automates cloud container security across the entire infrastructure stack, including registries, pre-production images, run-time environments, and DevOps toolchains. It works as a standalone service or in concert with Fidelis Halo’s server and cloud security services.
Fidelis Halo Container Secure

How Fidelis Container Secure™ Works

Security Across Every Stage of the Container Lifecycle.

Cloud operational efficiency

Fully Operational Within Minutes

Fidelis Container Secure™ is a fully self-contained, turnkey SaaS solution. You will be fully operational within minutes from initial account creation, including a full inventory, evaluation, and assessment of container instances, runtimes, and image repositories. Ongoing assessments of container hosts take less than 90 seconds, and new microagents on Docker hosts can be registered in less than 30 seconds.
Reduce cloud risk

Shift Security Left into the CICD Pipeline

Fidelis Container Secure™ natively connects with common continuous delivery pipeline tools, including Jenkins, to integrate security assessments into the development process. It integrates with nearly any DevOps tool using the bidirectional REST API, including Jira, jFrog Artifactory, and more, to include system owners as active participants in your enterprise security strategy.
Automated cloud Remediation

Kubernetes-Native DaemonSet Deployment

The Kubernetes-native DaemonSet support automates deployment of the Fidelis Halo microagent on every Kubernetes node for easy security management. The 2 MB Fidelis Halo microagent, available for Windows and Linux, secures your containerized environments through a simple policy assignment in the Fidelis Halo Portal. Each monitored node is evaluated against its container image database and applied policies to uncover known vulnerabilities and violations.

One Portal. Complete Container Visibility.

The Fidelis Halo Portal and API streamline security management by consolidating all configuration, management, alert, and response under a single platform, regardless of how diverse your containerized environment is. Create policies for containerized application infrastructures and apply them uniformly across any number of cloud service providers, cloud accounts, virtual machines, or bare metal hosts. All data is maintained in a single portal with interactive dashboards and prioritized alerts.

Benefits of Fidelis Container Secure™

Give Your Organization the Power to

1. Keep Pace: Automatically discover and evaluate containerized environments

Continuous Discovery and Inventory

Automatically discover, inventory, and evaluate containerized environments and assets, including container instances, host systems, image repositories, IaaS accounts, and Container-as-a-Service from AWS, Azure, and GCP, keeping pace with rapidly changing environments.

Attack Surface Reduction

Continually monitor container stacks to detect new vulnerabilities and exposures introduced by innocent changes or malicious activity, expose rogue containers in real time, and accelerate remediation to thwart attacks before they cause damage to your enterprise.

Full-Stack Host Protection

Detect vulnerabilities in host operating systems, container runtimes, orchestration configurations, unpatched packages, access privileges, security control configurations, network services, and process allowlists and blocklists, protecting containerized applications from the host up.

Automated Remediation Assistance

Integrate with DevOps tools to provide alerts in real time. DevOps teams receive best-practice remediation guidance with every alert, delivered through the tools they already use, including Jira, Slack, and ServiceNow. Quarantine suspected rogue containers within seconds of detection.

Intrusion Detection and Response

Automatically detect Docker host and Kubernetes node intrusions through log monitoring, file and system integrity monitoring, and intrusion detection. Rule updates happen automatically, keeping your containerized environments secure as new threats emerge, and cloud security best practices evolve.

Technology Integrations That Strengthen Your Endpoint Security

To provide enterprises with improved visibility throughout their endpoint environments, Fidelis Security® collaborates with top security platforms. These interfaces enable security teams to identify threats more quickly and react more precisely.
AWS Logo
Devo Logo
Gigamon Logo
Azure Logo
Trellix Logo
ZScaler Logo
vmware Logo
Forescout Logo
Google Cloud Logo
McAfee Logo
PaloAltoNetworks Logo
Splunk Logo

Threat Protection Offered by Fidelis Container Secure

Rogue Container and Image Threats

Detect rogue containers instantiated from unauthorized or unknown images in real time. Fidelis Container Secure™ continuously scans images across registries for software vulnerabilities, scans images pushed to registries and automatically passes or fails builds via integration with CI tools before they ever reach production.

Credential Scraping and Privilege Abuse

Once malware gains access to a container environment, it frequently targets credentials such as SSH keys, cloud access keys, access tokens, and Kubernetes service tokens. Fidelis Container Secure™ detects privileged, writable, and interactive containers and monitors access privileges and security control configurations to block credential abuse paths.

Network-Based and Lateral Movement Threats

Fidelis Container Secure™ segments your container host network to reduce the risk of lateral movement, and proactively blocks unsolicited inbound and outbound communication. File integrity monitoring for containers at rest and runtime, combined with intrusion detection on Docker hosts and Kubernetes nodes, closes the paths attackers rely on to move within the cluster.

Why are organizations choosing Fidelis Container Secure™ over every other solution?

Security is built into the pipeline, not bolted on after deployment.

Related Resources

Frequently Asked Questions

What is Fidelis Container Secure™ and how does it differ from traditional security tools?

Fidelis Container Secure™ is the container security service of the Fidelis CloudPassage Halo® platform. It automates security and compliance for Docker, Kubernetes, and continuous-delivery pipeline infrastructure, and validates security across the entire infrastructure stack for containers, including registries, pre-production images, run-time environments, and DevOps toolchains. Unlike traditional security tools, which were not designed to solve the unique challenges of containerized environments, Fidelis Container Secure™ works in even the fastest-moving, ephemeral containerized environments without becoming a bottleneck to rapid application development and deployment.

Fidelis Container Secure™ supports Docker CE, Docker EE, and Containerd as container runtime engines. Infrastructure coverage includes Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), OpenStack, VMware, and bare metal. Image registries supported include Docker Private Registry, Amazon ECR, and jFrog Artifactory. Container host operating systems include Amazon Linux, Ubuntu, CentOS, RHEL, Debian, and CoreOS. CICD integrations cover Jenkins, Bamboo, TeamCity, Circle CI, Travis CI, and more, with additional integrations via REST API, SIEM tools (Sumo Logic, Splunk), Slack, and JIRA.
Fidelis Halo’s policy library contains common best-practice and compliance policies and rules for containers, Kubernetes, Docker hosts, and runtime environments. All rules are based on CIS Benchmarks, PCI, HIPAA, SysTrust/SOC 2, and best practices determined by the Fidelis Halo Threat Intelligence team. Rule updates happen automatically, keeping environments secure as new threats emerge. Fidelis Container Secure™ also automates file integrity monitoring for containers at rest and at runtime, tracks containers through their full lifecycle including Docker events, and exports identified issues to meet compliance reporting requirements.