Feature Set Positioning Overview
|
CWPP (Professional Edition) | Basic host security hardening | 12 USD per host per month | SMBs primarily using CVM and requiring basic protection |
CWPP (Flagship Edition) | Complete CWPP protection + compliance | 27 USD per host per month | Medium and large enterprises with international security standard compliance requirements |
Container security | Cluster (node + cluster) hardening + compliance | Node security: 27 USD per host per month Cluster security: 6.75 USD per core per month | Medium and large enterprises that have adopted containers/K8s at scale and need node hardening+cluster runtime protection+compliance baselines |
Container image risk | Image security risk governance | USD 0.1/image | Medium and large enterprises with CI/CD image build processes that need to block image-layer security risks before launch |
The following modules can be purchased separately and additively across all paid editions, with no edition restrictions:
|
Cloud Product Configuration Check | Check for misconfigurations in cloud products such as databases, buckets, and security groups. | Enterprises with a wide variety of cloud products and high configuration risks |
Data Security Posture | Sort out sensitive data distribution and data compliance risks. | Enterprises with Data Security Law/Personal Information Protection Law compliance requirements |
Log Analysis | Retain raw logs, perform deep search, and conduct compliance audit. | Enterprises with compliance log retention requirements or in-depth traceability needs |
Application Protection | Web application layer security protection | Scenarios with intense security confrontation, and enterprise businesses requiring application-layer protection |
TencentCloud API Risk Governance | Manage API exposure surface and perform deep checking for authentication risks | Enterprises with numerous APIs and complex services |
Edition Feature Comparison Overview
|
Asset Center (Hosts/Containers/Cloud Assets) | ✅ | ✅ | ✅ | ✅ |
Emergency Vulnerability Detection | ✅ | ✅ | ✅ | ✅ |
Alarm Center (Remote Login) | ✅ | ✅ | ✅ | ✅ |
AI Workbench | ❌ | ✅ | ✅ | ✅ |
One-Click Fix for Linux/Windows/Web-CMS Vulnerabilities | ❌ | ✅ | ✅ | ✅ |
Baseline Detection of Weak Passwords | ❌ | ✅ | ✅ | ✅ |
Alarm Center (Anti-Virus) | ❌ | ✅ | ✅ | ✅ |
Virtual Patching for Vulnerabilities | ❌ | ❌ | ✅ | ✅ |
Application Vulnerability Detection | ❌ | ❌ | ✅ | ✅ |
Compliance baselines such as international security standards | ❌ | ❌ | ✅ | ✅ |
Cloud Perimeter Analysis | ❌ | ❌ | Open beta | Open beta |
AI Agent Security | ❌ | ❌ | ✅ | ✅ |
Ransomware Detection | ❌ | ❌ | ✅ | ✅ |
Core File Monitoring | ❌ | ❌ | ✅ | ✅ |
Alarm Center (Advanced Host Threat Detection) | ❌ | ❌ | ✅ | ✅ |
Container Runtime Threat Detection | ❌ | ❌ | ❌ | ✅ |
K8S API Security Audit | ❌ | ❌ | ❌ | ✅ |
IaC Risk Governance | ❌ | ❌ | ❌ | ✅ |
Container Compliance Baseline Governance | ❌ | ❌ | ❌ | ✅ |
Cloud Product Configuration Check | On-demand purchase | On-demand purchase | On-demand purchase | On-demand purchase |
Data Security Posture | On-demand purchase | On-demand purchase | On-demand purchase | On-demand purchase |
Log Analysis | On-demand purchase | On-demand purchase | On-demand purchase | On-demand purchase |
Application Protection | On-demand purchase | On-demand purchase | On-demand purchase | On-demand purchase |
TencentCloud API Risk Governance | On-demand purchase | On-demand purchase | On-demand purchase | On-demand purchase |
Container image risk | On-demand purchase | On-demand purchase | On-demand purchase | On-demand purchase |
Detailed Explanation of Editions
CWPP (Professional Edition)
Enterprise Characteristics
Cloud assets primarily consist of CVMs.
It faces basic intrusion threats such as brute-force attacks, trojans, and abnormal logins.
In the early stages of security construction, a core host protection baseline must be established at a reasonable cost.
Weak password management.
Core Capabilities Added Compared to the Free Edition
|
One-Click Vulnerability Fixing | Supports one-click fix for Linux / Windows / Web-CMS vulnerabilities. |
Application Vulnerability Detection | Comprehensively checking for weak passwords in system services and vulnerabilities in application services. |
Weak Password Baseline | Automatically discovering weak password configuration risks in the system. |
Alarm Center (Anti-Virus) | Receiving core alarms for malicious samples, host intrusions, abnormal logins, malicious processes, and so on. |
Capabilities Not Included in the Professional Edition and Available in the Ultimate Edition
International security standard compliance baseline checking.
Advanced threat detection capabilities (identification of complex attacks such as APTs).
Critical file monitoring, with tamper detection for key files.
Typical Scenario: An e-commerce company with 30 CVMs, which had previously suffered SSH brute-force attacks, selected the Professional Edition. This enabled one-click vulnerability fixing, weak password detection, and intrusion alarms, allowing the company to complete its host protection baseline construction at a reasonable cost.
CWPP (Flagship Edition)
Enterprise Characteristics
There are explicit international security standard compliance requirement check items.
The asset scale is large (more than 50 servers), and the security exposure surface is broad.
A dedicated security team exists, requiring comprehensive threat detection and response capabilities.
It has experienced advanced attacks such as APTs, or operates in an industry with high security risks.
Core Capabilities Added Compared to the Professional Edition
|
Compliance Baseline for International Security Standards | Built-in international security standards and Tencent Cloud baseline standards, with support for one-click compliance checking. |
Cloud Perimeter Analysis | Sort out the internet-exposed attack surface and identify unnecessary port openings and missing access controls. |
Advanced Threat Detection | The alarm center is upgraded to cover complex attack patterns such as APT. |
Core File Monitoring | Real-time tamper-proof monitoring for critical system files and Web pages. |
AI Agent Security | Security management and risk identification for AI agent assets |
Container Security
Enterprise Characteristics
Docker/Kubernetes has been adopted at scale, with a large number of container nodes and clusters, and containers have become the core runtime environment for business.
You have encountered runtime security incidents such as container escapes, malicious mining, or abnormal process injection, or you have clear concerns about such risks.
There are international security standard compliance requirements, and the compliance scope has been extended to the container and K8s level.
You use multi-cloud or hybrid cloud K8s clusters but lack a unified means of visualizing cluster configurations and access risks.
Core Capabilities Added Compared to CWPP Ultimate Edition
|
Container Runtime Threat Detection | Detects abnormal processes, escape behaviors, malicious mining, reverse shells, and other runtime attack behaviors in containers |
K8S API Security Audit | Audits Kubernetes API Server access behaviors and identifies risky operations such as unauthorized access and abnormal calls. |
IaC Risk Governance | Scans infrastructure code such as Dockerfile, Helm Chart, and K8s YAML before deployment to identify configuration risks in advance. |
Container Compliance Baseline Governance | Built-in container-specific compliance baselines such as international security standards, with support for one-click checking of cluster compliance status. |
Capabilities that still need to be added on demand.
The image-layer security risks (including detection of vulnerabilities, malware, and sensitive information in the early CI/CD stages) require the separate purchase of the "container image risk" module.
If deep defense and attack protection is required for applications in containers, it is still recommended to add the "application protection" module.
Typical Scenario
Typical Scenario 1 (Compliance-Driven): A healthcare enterprise must pass international security standard baseline checks every year to reduce the workload of audit preparation.
Typical Scenario 2 (Advanced Threats): An enterprise security team discovered a suspicious process, but no record existed in the alarm center. Through log analysis and proactive investigation based on raw logs, the team successfully identified a covert APT attack that evaded rule-based detection.
Typical Scenario 3 (Container Security): An internet company has fully containerized its core business and manages 20 K8s clusters and 300+ nodes. Previously, CWPP alone could not adequately cover risks such as container escapes and K8s API abuse. After container security was added, runtime detection identified a mining program attempting to access host resources through a container escape and blocked it in time. Meanwhile, IaC risk governance intercepted multiple high-risk Dockerfile configuration errors before deployment.
FAQs
Q: When will the free edition be upgraded?
A: Immediate upgrade is recommended if any of the following occurs: ① A brute-force attack or intrusion event is encountered. ② There is a need for ransomware protection or file monitoring. ③ There are vulnerabilities that need to be fixed quickly. ④ There are international security standard compliance requirements.
Q: How do I select the most suitable module for on-demand procurement?
A: Add modules on demand based on actual business pain points:
If you have compliance log retention requirements, add the Log Analysis module.
If you have a wide variety of cloud products and high configuration risks, add the Cloud Product Configuration Check module.
If you have data security compliance requirements, add the DSPM module.
If you have intense security attack and defense scenarios, add the Application Protection module.
If you need protection but cannot install a client, add the Snapshot Detection module.
Q: What is the relationship between container security and container image risk? Do they have to be purchased together?
A: The two cover different stages of container security and are not mandatory to purchase together. Container Image Risk focuses on pre-deployment image-layer risk governance, including scanning for vulnerabilities, malicious files, and sensitive information. Container Security focuses on post-deployment node hardening, cluster protection, and runtime detection. If you only need to intercept risks during the build stage, you can purchase Container Image Risk separately. If you already have containerized production clusters, we recommend combining the two to achieve full lifecycle protection from image building to runtime.
Q: Can CWPP and Container Security share the same hosts?
A: The "Node Security" billing item in Container Security is essentially CWPP Ultimate Edition (USD 27/host/month), which protects the host machines that run containers. "Cluster Security" (USD 6.75/core/month) is a container-specific capability that provides cluster, K8s API, and runtime protection. The two must be used together, and you cannot purchase only Cluster Security while skipping node protection.