Microsoft Defender for Cloud is a Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) for Azure, on-premises, and multicloud (Amazon AWS and Google GCP) resources.
N/A
SUSE Security
Score 8.0 out of 10
N/A
SUSE® Security (formerly NeuVector) provides an end-to-end container security platform. This includes end-to-end vulnerability scanning and complete run-time protection for containers, pods and hosts.
I think it's good for cloud-native companies. A company that, from day zero, they're like, "We're going cloud, and this is how we're going to do it." They get it. It works well for them. Smaller organizations that are under X amount of resources- I don't know what that X might mean- but I feel like it plays well in smaller, more nimble organizations. If you're an older organization or if you're extremely large, it starts becoming a little difficult to manage at scale. And you have to sometimes throw bodies at the problem. Maybe not the most eloquent way of saying it, but that's what it feels like.
SUSE NeuVector is exceptional when you want to make your Kubernetes cluster secure. You can limit network connections, scan containers, container registries and Kubernetes nodes for vulnerable software, forbid running specific commands on certain or all containers. You can enable security for individual containers - when SUSE NeuVector has learned container specifics. That's why you can deploy SUSE NeuVector on production Kubernetes clusters where you are already running conteiners - it will not break anything.
It's really well laid out, with an easy-to-use, accessible UI.
With Microsoft Defender for Cloud, it has everything you need with the Safelink attachment, the Safelink emails for URL, the way it scans those URLs and attachments within the product, and you're seeing the results. And that adds an extra layer of security for the user, so you feel comfortable knowing the product monitors those. That's something I really like about that product.
Integrations with on-premise workloads can sometimes be challenging. Needs improvement and well standardised integration points
Vulnerability categories can be difficult to understand. It should allow teams to focus on critical findings and help them keep aside low-severity or suppressed vulnerabilities
Pricing can be improved as it can be over-priced for smaller businesses and would potentially affect their ROI due to the small scale
It is a great product that integrates nicely when running an Azure platform and even multi-cloud environment. Not looking for point-solutions but a suite that answers most requirements. It is very comfortable being able to use KQL, workbooks and automation that is native to the azure platform
I would give a rating of nine for the following reasons: - easy to use dashboard with a clear view of our entire security posture -security, recommendations are easy and practical to follow -helps prioritise high risk issues instead of treating all alerts equally
I believe Microsoft Defender for Cloud stacks up well against the other tools we looked at. It is native to the Azure platform and provides the same insights as the other tools. We selected Microsoft Defender for Cloud because it integrates well with the Azure resources and gives the needed insight, security alerts and recommendations.
SUSE NeuVector is deployed on your Kubernetes, and data does not leave your data center. Sysdig is a cloud platform - you have no full control over what happens with your data. Also, SUSE NeuVector has a capability to prevent specific command execution ir containers, but Sysdig does not have such ability. Sysdig is not an open-source solution, but SUSE NeuVector is.