
SUSE Container Security Platform
Open-source container security providing Layer 7 firewall, deep packet inspection, and zero-trust runtime protection.
Vendor Information
SUSE Container Security Platform Overview
SUSE Security (formerly NeuVector) is the only 100% open-source, zero-trust container security platform delivering full lifecycle protection from build to runtime for Kubernetes environments. Unlike proprietary container security solutions, SUSE Security provides end-to-end vulnerability scanning throughout the CI/CD pipeline and into production, with patented Deep Packet Inspection (DPI) technology and a true Layer 7 container firewall that secures east-west traffic between containers and pods.
The platform features automated behavioral learning that discovers application patterns and creates security policies, combined with AI-driven anomaly detection to identify and block network, packet, zero-day, and application attacks including Distributed Denial of Service (DDoS) and Domain Name System (DNS) threats. Security policies can be managed as code using Kubernetes Custom Resource Definitions (CRDs) enabling GitOps workflows, while automated compliance auditing using Docker Bench and Kubernetes Center for Internet Security (CIS) Benchmark tests generates risk scores and compliance reports for Payment Card Industry Data Security Standard (PCI-DSS), Health Insurance Portability and Accountability Act (HIPAA), and General Data Protection Regulation (GDPR).
Originally founded in 2015 and acquired by SUSE in October 2021 for $130M, SUSE Security was open-sourced in January 2022 making it the industry's first fully open-source container security platform. The platform integrates seamlessly with SUSE Rancher for multi-cluster security management and supports all major Kubernetes distributions including Red Hat OpenShift, VMware Tanzu, Amazon Elastic Kubernetes Service (EKS), Google Kubernetes Engine (GKE), and Azure Kubernetes Service (AKS), serving regulated industries including financial services, healthcare, and government sectors.
Key Capabilities
Standardized capabilities mapped to this product's security niche
Scans container image layers for OS package CVEs and application dependency vulnerabilities at build time, registry push, or pre-deployment, before execution.
Captures a continuous record of workload events (process, network, file, syscall), for forensic investigation: differentiation is event retention period, query performance, and contextual enrichment.
Enforces pod security standards, network policies, and RBAC controls across Kubernetes clusters, blocking non-compliant workload deployments and detecting policy drift.
Detects in-memory exploitation techniques (shellcode injection, heap spraying, ROP chains), in running workloads without relying on file-based signatures.
Monitors process execution, network connections, and file system activity in running workloads using a kernel agent, eBPF sensor, or sidecar container to detect behavioral anomalies and known attack patterns.
Agent-based enforcement installs a lightweight agent on each host and enforces policy at the OS network stack. Agentless relies on upstream network controls (SDN, firewall). Each has different coverage and operational tradeoffs.
Discovers actual application communication flows by observing traffic before policy creation, producing a dependency map that forms the basis for allow-list policy without manual documentation.
Evaluates proposed segmentation policies against observed traffic to identify what legitimate connections would be blocked, enabling policy validation without a production enforcement change.
Applies consistent microsegmentation policy to cloud VMs and containers alongside on-premises workloads, using cloud-native enforcement mechanisms (security groups, NSGs) under unified policy.
Enforces identity-based allow policies (user identity, workload identity, device posture), rather than IP-based rules, policy follows the workload regardless of network location.
Blocks SMB, RDP, and WMI connections between endpoints by default, preventing ransomware from moving laterally via common network shares and remote management protocols.
Integrations
Compatible tools and platforms
Solution Details
Deployment Options
Where and how this solution can be deployed
Support Channels
Available support and communication options
Pricing Model
How this solution is priced
How to buy
This profile hasn’t been claimed yet. Contact the vendor directly for pricing and purchasing options.
Is this your company?
Claim Your Profile