Container Security
Container security across the full lifecycle — from image scan to runtime.
Kaspersky Container Security (KCS) covers every stage of a containerized app’s lifecycle, from development to operation. Traditional security does not suit container architecture, and 85% of companies suffered more than one Kubernetes incident in a year. KCS delivers multi-level protection from container images to the host OS, automates compliance audits, and supports DevSecOps — shortening time to market. Part of Kaspersky Cloud Workload Security, it is deployed and operated by Faltrox.
Overview
What Container Security is
Containerization accelerates app design and delivery, but traditional security solutions are not built for its architecture — and the consequences are real: 85% of companies had more than one Kubernetes incident in the last 12 months, 39% reported a data leak from container security issues, and 38% lost revenue. Kaspersky Container Security protects the containerized environment specifically.
It secures every stage — image and configuration scanning in the registry and CI/CD (shift-left), infrastructure protection at launch, and runtime protection of running containers, cluster nodes, and the orchestrator. It maps to the MITRE ATT&CK Containers Matrix, automates compliance audits against NIST, Kaspersky, and customer benchmarks, and visualises and inventories cluster resources. Four components (a scanner, node and kube agents, and a control server) install into the cluster, transmitting events to SIEM and XDR. Faltrox operates it as part of your cloud workload security.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Container Images
Scans images and configuration files in the registry and CI/CD before they ever run.
Kubernetes Orchestrators
Protects cluster nodes and the orchestrator, monitoring processes and events in the cluster.
Runtime Containers
Enforces runtime container security with launch control and running-container protection.
Host OS
Multi-level protection reaches down to the host operating system beneath the containers.
Compliance Audits
Automated best-practice audits against NIST, Kaspersky, and customer-defined benchmarks.
MITRE ATT&CK Containers
Coverage mapped to the ATT&CK Containers Matrix of adversary techniques.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Scan
The KCS Scanner checks image registries and CI/CD pipelines for vulnerabilities and misconfiguration, reducing build-stage risk.
- 02
Enforce at Launch
Launch control and configuration analysis gate what is allowed to run, implementing security at deployment.
- 03
Protect Runtime
KCS Node and Kube Agents detect vulnerabilities and file threats at container, cluster, and orchestrator levels in real time.
- 04
Audit
Automated compliance checks against NIST, Kaspersky, and custom benchmarks produce transparent reporting.
- 05
Correlate
The Control Server aggregates detected events and transmits cluster logs to SIEM and XDR for cross-source correlation.
Capabilities
Key capabilities
Image & IaC Scanning
The KCS Scanner checks image registries and infrastructure-as-code as part of CI/CD to reduce build-stage risk.
CI/CD & Registry Integration
Integrates with image registries and CI/CD platforms to shift security left into development.
Runtime Protection
The Node Agent enforces runtime container security, detecting issues at container and cluster levels on each node.
Orchestrator Protection
The Kube Agent detects vulnerabilities and file threats at orchestrator level, ensuring host OS security.
MITRE ATT&CK Coverage
Covers key malicious techniques targeting container infrastructure per the ATT&CK Containers Matrix.
Compliance Audits
Best-practice audits against NIST, Kaspersky, and customer databases with transparent reporting automate compliance.
Resource Visualisation
Fully customisable widgets and transparent inventory reveal cross-section data on cluster resources.
SIEM & XDR Integration
Cluster event logs feed directly into SIEM and XDR for context, telemetry, and forensic insight.
Works with
Part of the platform
Kaspersky products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Kaspersky Container Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Why do containers need dedicated security?
Traditional security solutions are not suited to the architectural features of containerized environments, and the incident data is stark — 85% of companies had more than one Kubernetes incident in a year. KCS protects the specifics: images, orchestrator, runtime, and host OS.
02Does it shift security left into development?
Yes. The KCS Scanner integrates with image registries and CI/CD platforms to scan images and infrastructure-as-code before deployment, supporting a DevSecOps approach and reducing build-stage risk rather than only protecting at runtime.
03What runtime protection does it provide?
Node and Kube Agents installed into the cluster enforce runtime container security, protect cluster nodes and the orchestrator, and monitor processes and events — with launch control and configuration analysis gating what runs.
04How does it help with compliance?
It automates compliance audits with best-practice checks against NIST, Kaspersky, and customer-defined benchmarks, and provides transparent reporting — freeing your security team from manual audit work.
05How does Faltrox operate it?
We install the scanner and agents, integrate them with your CI/CD and registries, configure the benchmarks and runtime policies, and wire events into your SIEM/XDR — delivering managed container security across the pipeline and cluster.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us