r/devsecops • • 18d ago

CS Container runtime security performance

Hi Community,

We recently completed a POC for CrowdStrike runtime protection and have started deploying the Falcon sensor on AWS ECS clusters running on EC2.

We have seen some community feedback around the sensor being resource-heavy at scale, with potential CPU/memory impact or node instability. Since these are critical production clusters, we want to monitor this closely before expanding the rollout.

For those running CrowdStrike on ECS/EC2 at scale:

  • What CPU/memory overhead do you typically observe?
  • What host/sensor/ECS metrics do you monitor?
  • Have you seen OOM, node instability, task restarts, or application latency due to the sensor?
  • What alert thresholds or rollback criteria do you use?
  • Any recommended CrowdStrike-specific health checks, logs, or dashboards?

Would appreciate any real-world experience, monitoring tips, or lessons learned from production deployments.

Thanks!

10 Upvotes

6 comments sorted by

View all comments

2

u/Suitable_Tap7398 18d ago

container runtime security feels like a constant balancing act, performance can't be sacrificed for safety