Shield Stratus · AWS & Azure

In the Cloud. In Line. In Charge.

Cloud-native enforcement for AWS and Azure workloads. Bi-directional. In-line. No agent. Powered by the Global Threat Engine. 1 Gbps and up.

Book a Demo → See How Shield Works
Shield Stratus cloud network enforcement diagram
Why Shield Stratus

Cloud Protection That Deploys in Minutes. Not Sprints.

GA

Cloud-native. Generally Available on AWS and Azure Marketplace.

8.5B

Powered by 25 years of IP and DNS reputation. 8.5 billion combinations.

2-Way

Bi-directional inspection across every flow. No sampling. No baselining.

The Platform

One Console for All Your Cloud Enforcement.

Shield Stratus sits in-line in your cloud network and blocks malicious connections at the connection layer. No firewall rules to maintain. No agents on workloads. Bi-directional enforcement powered by the Global Threat Engine.

Shield Command Hub Overview: Network Health, Threat Countries, Risk Categories, AI Insights
Where It Fits

Shield Stratus. Pick Your Cloud. Deploy in Minutes.

Today live on AWS and Azure Marketplace. GCP support on the roadmap. Pick the cloud where your workloads live, deploy Stratus from the marketplace, and your bi-directional enforcement is active within the hour.

Book a Demo →
AWSAzureGCP
AvailabilityGenerally Available on AWS MarketplaceGenerally Available on Azure MarketplaceOn the roadmap
Deployment MethodAWS Gateway Load Balancer target. Deploy from AWS Marketplace.Azure load balancer integration. Deploy from Azure Marketplace.Coming soon
Throughput1 Gbps and up1 Gbps and upComing soon
Setup TimeMinutesMinutesComing soon
Bi-Directional EnforcementComing soon
Observe ModeComing soon
Protect ModeComing soon
Global Threat EngineComing soon
Shield Command Hub IntegrationComing soon
Fixed Hourly PricingComing soon
The Approach

Hardened at the Connection Layer. Not the Perimeter.

Shield Stratus enforces at the cloud network level, inspecting every inbound and outbound connection in real time against the Global Threat Engine. No agents. No sampling. No firewall rule sprawl.

Bi-Directional. In-Line. Always On.

Shield Stratus inspects and blocks both inbound and outbound connections. In Observe Mode, administrators gain full visibility. In Protect Mode, Shield blocks malicious connections at the connection layer before they reach your workloads.

No Agents. No Firewall Rules to Maintain.

Shield Stratus sits in-line in your cloud network using AWS Gateway Load Balancer or Azure load balancer integration. Traffic passes through the appliance transparently. Your workloads stay clean, unmodified, and protected without configuration sprawl.

Managed Through Shield Command Hub.

One console for unified visibility and control across all your Shield enforcement platforms. Cloud, on-premise, and endpoint all report into Shield Command Hub. See threats, manage modes, and run software updates without leaving a single pane of glass.

The Capabilities

No Connection Passes Without Inspection.

What Shield Stratus blocks, how it deploys, and how it scales with your cloud.

From AWS Marketplace to Enforcement in Under an Hour.

Shield Stratus deploys as a Gateway Load Balancer target on AWS or as an Azure load balancer integration on Azure. No complex networking changes. No custom firewall policies to architect from scratch. Pick your cloud, subscribe from the marketplace, configure your load balancer target, and bi-directional enforcement is active. Fixed hourly pricing on both platforms simplifies billing for direct customers and MSP partners alike.

In-Line Enforcement. Every Packet. Both Directions.

Shield Stratus sits in the data path of your cloud network. Every connection, inbound and outbound, passes through the Global Threat Engine for real-time evaluation. No traffic sampling that lets threats slip through. No baseline learning period where your environment is exposed. From the moment Shield Stratus is active, every flow is evaluated and every confirmed malicious connection is blocked.

25 Years of Threat Intelligence. 8.5 Billion Combinations.

Every enforcement decision is powered by the Global Threat Engine. 25 years of IP and DNS reputation data. 8.5 billion combinations built and maintained by Intrusion since 2001. Owned, not licensed. Updated continuously. The same intelligence that powers Shield OnPremise, Shield Endpoint, and Shield Sentinel, now available to protect your AWS and Azure workloads with no additional integration required.

From the Blog

Cloud Security Insights.

FAQ

Cloud Deployment Questions.

No. Shield Stratus inspects and enforces in both directions. Depending on deployment mode (Observe or Protect), administrators can monitor or actively block both inbound and outbound traffic for full bi-directional security visibility and control.
Shield Stratus is powered by the Global Threat Engine. 25 years of IP and DNS reputation data. 8.5 billion combinations built since 2001. Owned by Intrusion, not licensed, not aggregated. Managed through Shield Command Hub for unified visibility and control across all enforcement platforms.
Shield Stratus software updates can be performed by launching a new AMI of the updated version, or by an on-demand user-requested software update via Shield Command Hub.
Customers select the vertical scaling (instance size) when Shield Stratus is launched. The underlying technology supports Auto Scaling Groups for horizontal scaling. Management of Shield Stratus instances in auto-scaled groups via Shield Command Hub is on the roadmap.
Shield Stratus follows a fixed hourly pricing model based on instance size. This simplifies billing for both direct customers and MSP partners.
On AWS, Shield Stratus natively integrates with AWS Gateway Load Balancer using the GENEVE protocol for seamless in-line traffic inspection. On Azure, Shield Stratus integrates with Azure load balancing for the same in-line deployment pattern. GCP integration is on the roadmap.

Stop Watching Cloud Traffic.
Start Blocking It.

See how Shield Stratus protects your AWS and Azure workloads in under thirty minutes.

Book a Demo → Run a Proof of Value