Provides network intrusion protection for cloud workloads through signature-based detection and custom user signatures. Supports AWS, Azure and on-premise environments with real-time threat detection and response. Features include Tap, Bypass, Emergency OFF, and IDS mode for operational stability, along with Open API integration capabilities. Functions as part of a broader workload protection platform that includes firewall, application control, and anti-malware capabilities for hybrid infrastructure security.