Cloud-native enforcement for AWS and Azure workloads. Bi-directional. In-line. No agent. Powered by the Global Threat Engine. 1 Gbps and up.
Book a Demo → See How Shield WorksCloud-native. Generally Available on AWS and Azure Marketplace.
Powered by 25 years of IP and DNS reputation. 8.5 billion combinations.
Bi-directional inspection across every flow. No sampling. No baselining.
Shield Stratus sits in-line in your cloud network and blocks malicious connections at the connection layer. No firewall rules to maintain. No agents on workloads. Bi-directional enforcement powered by the Global Threat Engine.

Today live on AWS and Azure Marketplace. GCP support on the roadmap. Pick the cloud where your workloads live, deploy Stratus from the marketplace, and your bi-directional enforcement is active within the hour.
| AWS | Azure | GCP | |
|---|---|---|---|
| Availability | Generally Available on AWS Marketplace | Generally Available on Azure Marketplace | On the roadmap |
| Deployment Method | AWS Gateway Load Balancer target. Deploy from AWS Marketplace. | Azure load balancer integration. Deploy from Azure Marketplace. | Coming soon |
| Throughput | 1 Gbps and up | 1 Gbps and up | Coming soon |
| Setup Time | Minutes | Minutes | Coming soon |
| Bi-Directional Enforcement | ✓ | ✓ | Coming soon |
| Observe Mode | ✓ | ✓ | Coming soon |
| Protect Mode | ✓ | ✓ | Coming soon |
| Global Threat Engine | ✓ | ✓ | Coming soon |
| Shield Command Hub Integration | ✓ | ✓ | Coming soon |
| Fixed Hourly Pricing | ✓ | ✓ | Coming soon |
Shield Stratus enforces at the cloud network level, inspecting every inbound and outbound connection in real time against the Global Threat Engine. No agents. No sampling. No firewall rule sprawl.
Shield Stratus inspects and blocks both inbound and outbound connections. In Observe Mode, administrators gain full visibility. In Protect Mode, Shield blocks malicious connections at the connection layer before they reach your workloads.
Shield Stratus sits in-line in your cloud network using AWS Gateway Load Balancer or Azure load balancer integration. Traffic passes through the appliance transparently. Your workloads stay clean, unmodified, and protected without configuration sprawl.
One console for unified visibility and control across all your Shield enforcement platforms. Cloud, on-premise, and endpoint all report into Shield Command Hub. See threats, manage modes, and run software updates without leaving a single pane of glass.
What Shield Stratus blocks, how it deploys, and how it scales with your cloud.
Shield Stratus deploys as a Gateway Load Balancer target on AWS or as an Azure load balancer integration on Azure. No complex networking changes. No custom firewall policies to architect from scratch. Pick your cloud, subscribe from the marketplace, configure your load balancer target, and bi-directional enforcement is active. Fixed hourly pricing on both platforms simplifies billing for direct customers and MSP partners alike.
Shield Stratus sits in the data path of your cloud network. Every connection, inbound and outbound, passes through the Global Threat Engine for real-time evaluation. No traffic sampling that lets threats slip through. No baseline learning period where your environment is exposed. From the moment Shield Stratus is active, every flow is evaluated and every confirmed malicious connection is blocked.
Every enforcement decision is powered by the Global Threat Engine. 25 years of IP and DNS reputation data. 8.5 billion combinations built and maintained by Intrusion since 2001. Owned, not licensed. Updated continuously. The same intelligence that powers Shield OnPremise, Shield Endpoint, and Shield Sentinel, now available to protect your AWS and Azure workloads with no additional integration required.
See how Shield Stratus protects your AWS and Azure workloads in under thirty minutes.