---
title: F5 Distributed Cloud App Infrastructure Protection (AIP) Reviews
meta_title: 'F5 Distributed Cloud App Infrastructure Protection (AIP) Reviews 2026:
  Details, Pricing, & Features | G2'
meta_description: Filter 44 reviews by the users' company size, role or industry to
  find out how F5 Distributed Cloud App Infrastructure Protection (AIP) works for
  a business like yours.
aggregate_rating:
  rating_value: 4.4
  review_count: 44
  scale: '5'
date_modified: '2026-08-07'
parent_category:
  name: Cloud Security
  url: https://www.g2.com/categories/cloud-security
---


# F5 Distributed Cloud App Infrastructure Protection (AIP) Reviews
**Vendor:** F5  
**Category:** [Cloud Security Monitoring and Analytics Software](https://www.g2.com/categories/cloud-security-monitoring-and-analytics)  
**Average Rating:** 4.4/5.0  
**Total Reviews:** 44
## About F5 Distributed Cloud App Infrastructure Protection (AIP)
Distributed Cloud AIP, formerly known as Threat Stack, is the leader in cloud security and compliance for application infrastructures, helping companies securely leverage the business benefits of the cloud with proactive risk identification and high-efficacy threat detection across cloud workloads. Distributed Cloud AIP’s application infrastructure protection helps organizations improve operational efficiency by delivering full stack security observability across the cloud management console, host, container, orchestration, managed containers, and serverless layers. Distributed Cloud AIP helps organizations efficiently detect known risks at scale and quickly uncover anomalies throughout the environment. Distributed Cloud AIP helps organizations stay secure through comprehensive security monitoring with a combination of industry-leading telemetry collection, a robust ruleset for known threats, and ThreatML for vulnerability and anomaly detection. Security Services Customers also have the option of leveraging our human expertise with Distributed Cloud AIP Insights and Managed Security Services, our in-house Security Operations Center (SOC) that provides 24/7/365 monitoring of your cloud environment. Through both options, Distributed Cloud AIP aims to deliver visibility and response capabilities across the full stack, allowing organizations to leverage the benefits of modern computing environments, securely. Coupled with other F5 Distributed Cloud Services, customers get application and infrastructure protection. Because applications and APIs are only as secure as the infrastructure they run on. To learn more, visit https://www.f5.com/cloud/products/app-infrastructure-protection




## F5 Distributed Cloud App Infrastructure Protection (AIP) Reviews
  ### 1. Works, but slight annoyances

**Rating:** 4.0/5.0 stars

**Reviewed by:** Brad S. | Information Architect, Enterprise (> 1000 emp.)

**Reviewed Date:** April 19, 2023

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

The application provides seamless integration between systems on campus and systems off campus, as well as integrating with the campus-wide firewall and authenthication.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

When a session ends, you can't just simply log back in. If you do, it'll almost certainly kick you back out. You have to remember to close a window, then reconnect. Annoying.

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

The largest problem is wholesale integration with systems, and then broad marketing to users in a large organization on actually using the product. CS tickets increased quite a bit for normal every day users.

  ### 2. With Threat Stack, its relatively easy to accelerate our compliance & streamline security audits

**Rating:** 4.0/5.0 stars

**Reviewed by:** Shreya B. | Cloud Engineer, Information Technology and Services, Enterprise (> 1000 emp.)

**Reviewed Date:** November 19, 2022

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

Threat Stack gives us comprehensive cloud security & compliance management through its event-based monitoring feature. We can conveniently monitor our host instances, containers & K8 deployments in its centralized observability platform. It also provisions compliance & security governance for every telemetry layer of our cloud environments.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

Threat Stack effectively provides an intrusion detection platform that effectively filters out false positives & allows us to focus on critical alerts. All alert noise can be suppressed by simply using its predefined rule sets, thereby reducing our time & effort. Hence with Threat Stack, we can quickly identify anomalous behaviors in our cloud infrastructure.

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

Compared to other cloud security & compliance management platforms, Threat Stack is quick to process Mean-Time-To-Detect (MTTD) & Mean-Time-To-Know (MTTK) metrics. We evaluate our compliance audits from its compliance monitoring reports & opt for proactive risk reduction approaches. It also provides excellent remediation recommendations with rich cloud security insights & best practices to track suspicious activities & misconfigurations accurately.

  ### 3. F5 Cloud AIP

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer Networking | Mid-Market (51-1000 emp.)

**Reviewed Date:** May 31, 2023

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

Helps in precise monitoring of resources within the cloud environment and provides relevant alerts in case a vulnerability is observed.
Analytics and dashboard helps in identifying the risks.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

The User Interface can be enhanced.
Shortcuts should be provided to reach a particular resource rather than clicking through the traditional way.
Integration can be made easier.

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

Quite helpful in operational and security related monitoring of cloud based resources.
Investigating vulnerability related alerts helps in avoiding security risks and assists in its remediation.

  ### 4. Provides VPN Solutions

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Enterprise (> 1000 emp.)

**Reviewed Date:** April 26, 2023

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

1. I used this app to access VPN
2. Secure
3. I could access all my office related stuffs and it was fast too

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

There were frequent disconnections observed while using, but that is not a major con

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

It provides faster and secure solution to access office contents. It is easy to use and no proper knowledge or learning is needed to use this application. I used this app as VPN.

  ### 5. Great experience, easy to use

**Rating:** 3.5/5.0 stars

**Reviewed by:** Nicolás E. | Cloud Engineering Manager, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 18, 2021

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

I like you can apply a set of rules already predefined for SOC2

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

After the tool is reporting a vulnerability, if I fix it just right after, I need to wait until the other day to see the fix reflected on the report, so I do not like that I can not trigger a scan on demand.

I'll like to have a Jira integration, so when the tool is reporting a vulnerability can also filla ticket to track it, reporting is good but for goind beyond the line it will be good to report the vulnerability and also create a ticket like an action item for the team

**Recommendations to others considering F5 Distributed Cloud App Infrastructure Protection (AIP):**

The product is great, the setup is super straight forward, and the set of rules you can apply will make your life easy; we were using it for classic ec2 instances, but after moving to k8s we lose some features, the tracking for ssh is not so good as we had in classic ec2 implementation

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

IDS and FIM for being SOC2 compliance

  ### 6. The platform takes time to get used to at first, but after it became very intuitive

**Rating:** 3.5/5.0 stars

**Reviewed by:** Nithin D. | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 03, 2020

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

The color coordination! Easy for the eyes. Especially on how we can distinguish based off color of the type of Sev if either sev 1, sev 2, or sev 3 within alerts tab. Along with that the dashboard tab is very very easy to understand on whats going on.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

It just took time to get used to using the UI. Within the events tab it was first a bit hard to notice the parameters since it is in light colors, the ones that im talking about are: servers,argument,pid,command, etc. Not sure if this functionality is already there, but when viewing an alert in group view and then I click "select all", is there a way to suppress all alerts. As of now looks like we'd have to do one by one. For the dashboard tab, there is a lot of white space. Maybe we can use more of that white space to add more helpful analytics.

**Recommendations to others considering F5 Distributed Cloud App Infrastructure Protection (AIP):**

Look at tutorial videos before utilizing Threat Stack and also have proper basic fundamentals of networking. I would recommend others to use Threat Stack for infrastructure monitoring, vulnerability management, threat intelligence, and compliance reporting. This tool is a very helpful cloud security platform. Just like everything new to you, make sure to get some practice in learn the fundamentals first. Dont rush in like me or it will be chaotic to look at first.

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

Im currently not utilizing threatstack that much. Other team members can better answer that! The time I did utilize Threat stack was to determine which of our employees are logging into AWS without utilizing Multi Factor Authentication. Since this was an alert in Threat Stack as I believe a SEV 3, we were able to track down all the users and inform them to setup multi factor authentication for their account.

  ### 7. Good product, with some room for improvement

**Rating:** 3.5/5.0 stars

**Reviewed by:** Jesse B. | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 15, 2020

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

One of the best parts of using Threatstack has been the customer care team. They've been very diligent listening to our feedback and addressing it. They continually monitor and tune our alerts, alleviating some of that burden.

Kubernetes support has been good; the agents are very easy to deploy in our clusters.

The default rulesets are pretty comprehensive, although they require extensive tuning to filter out the noise.

We've seen steady improvement of the product over time. Even as I was writing this review, I was navigating around the product and found that some issues we used to have had been resolved. One good example of this was with CVE handling. It used to be impossible to see which CVEs had a matching security notice. Now I see that you can sort by whether a vulnerability has a security notice, making it much easier to find actionable CVEs.

The monthly wrap-up report and video call we do has been helpful in surfacing misconfigured services and unusual user behavior.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

The web interface can feel clunky at times. Some areas are less polished than others.

A LOT of tuning is required to eliminate noise. We still deal with a number of alerts that aren't actionable, but the Threatstack team continues to work on tuning them.

Being billed by agent hour adds up quickly and incentivizes monitoring the bare minimum number of servers. Also, having a certain allotment of agent hours each year and having to negotiate contract changes if we use more/less is a bit of a hassle. It'd be nicer to just have a flat-rate per agent and get billed for whatever we use each year.

Earlier on, the product had many deficiencies and bugs. Some components were broken, others were just not useful. This has improved over time though!

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

The most basic problem we needed to solve was IDS. Threat Stack does this well, both in our legacy EC2 instances as well as our newer Kubernetes clusters. We looked at implementing our own solution with open source tools, but the sheer effort to tune and develop the ruleset was too much compared to a managed solution like Threat Stack.

Vulnerability detection is another problem we're solving with Threat Stack. It helps us fulfill obligations to patch critical CVEs within our contractual timelines.

  ### 8. Threatstack is an integral component of our Security Operations. Great product, great support.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Steven W. | CISO and VP of IT Infrastructure, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 21, 2021

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

The ability to monitor your cloud environment combined with per-host monitoring provides good overall coverage of potential threats and software vulnerabilities. While ThreatML (Machine Learning) is in a nascent state, I believe ThreatStack will continue to improve its use of ML over time. It is fairly easy to tune alerting to your environment, and Threatstack support is very helpful when it comes to working with rule sets and suppressions.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

I would like to see better exportable reporting for Audits. Some alerts are not actionable or cannot be suppressed.

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

We were able to use Threatstack to provide evidence to our Auditors and Assessors to successfully become SOC and HITRUST certified.

  ### 9. Incredibly capable tool with an incredible depth and complexity in configuration.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Marketing and Advertising | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 01, 2020

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

Keeping on top of CVEs is fantastic, there's more open CVEs here than the Linux distro recognizes as needing to be patched. This is a very real picture of exactly how things are. As we've gone along in using Threatstack we're now moving to AWS and having Threatstack deployed there from the very beginning has been useful.

The rulesets are also incredibly useful and the ability to configure custom rules and exceptions is a strength.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

The complexity around hosts and ports and appropriately configuring everything to accept some things but not others. Custom rules are very powerful but holy cow it's tedious and feels as though one should be taking a fine grained approach but being a threat stack configuration expert is not a major part of the job.

**Recommendations to others considering F5 Distributed Cloud App Infrastructure Protection (AIP):**

This is a solution that is necessary for any SaaS company, but be careful about custom rules!

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

Our company is about to enter into SOC2 auditing. Prior to having Threatstack we were taking the approach of being reactive to security problems and doing our best to stay on top of things we were aware of. Now that we have Threatstack, we are no longer being as reactive and have begun to be proactive.

  ### 10. Security Engineer Perspective

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Insurance | Small-Business (50 or fewer emp.)

**Reviewed Date:** December 07, 2020

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

I like how simple it is to get up and running. It's great to setup and not have to worry about a complicated configuration process. There is a base set of rules already created and it is fairly simple to implement new rules for instance and Cloudtrail monitoring.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

Lack of feature set and log retention. Threatstack is great at having a baseline checks and monitors, but lacks some of the more advanced features. While they claim to have intelligence, there is no way for a user of the platform to view any types of intelligence. Rule creation is a bit tricky when you get into suppressions, there is no way to test a rule in combination with suppressions, you have to test each piece individually and hope it works all together. For the price point, Threatstack only keeps 3 days of logs which is completely useless and you must have a SIEM to forward the logs to in order to keep any sort of record of what is happening on your servers.

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

Threatstack solves the problem of having AV on our servers and monitoring of our Cloudtrail events. It also gives us the peace of mind that we have a reliable tool in our arsenal to help monitor our infrastructure.

  ### 11. ThreatStack - HIDS Solution

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Health, Wellness and Fitness | Enterprise (> 1000 emp.)

**Reviewed Date:** December 07, 2020

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

The way we can write rules and suppressions. Fits to custom needs.
The default rule set helps in customizing them.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

Could do better with UI to improve the usability of the tool specially with investigation of alerts and events.

**Recommendations to others considering F5 Distributed Cloud App Infrastructure Protection (AIP):**

Definitely easy to setup and use if you are administering it.  It can get little tricky while investigations on events initially but once you get used to it, you should be fine.

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

We are using ThreatStack as a Host based IDS solution for our compliance environment(PCI).
We can tune the monitoring rules as per our needs and grant exceptions.

  ### 12. Solid platform for aws threat detection, lacking features for other clouds

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 16, 2020

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

There services team is amazing and really make working with the entire a platform a joy. They are like a extension of our devsec ops team.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

The biggest issue we have is that they are primarily built around aws workloads. We have workloads that run in all three clouds and their isn't feature parody between clouds

**Recommendations to others considering F5 Distributed Cloud App Infrastructure Protection (AIP):**

Seriously consider leveraging the threatstack services in addition to their software, there service team is amazing.

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

We use threatstack as a solution for a lot of our soc2 controls

  ### 13. A Reassuring Watchful Eye

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Legal Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 14, 2020

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

The platform is always there monitoring our configuration and events without much overhead, alerting us to crucial items quickly

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

The interface can sometimes be a little overwhelming in places

**Recommendations to others considering F5 Distributed Cloud App Infrastructure Protection (AIP):**

Using Threatstack will help ensure you're capturing the cloud events that matter and also give you the reassurance that if someone makes a mistake with a config it will be flagged up quickly.

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

We're able to identify events that matter and easily escalate them to the right team

  ### 14. Valuable insight into threat exposure

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** December 04, 2020

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

real-time monitoring of system processes and alerting of security related events
simple installation and configuration management

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

search facility for system events lacks flexibility

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

Ensure compliance to security principles
Monitoring and breach detection of server infrastructure

  ### 15. Threat Stack for Complaince

**Rating:** 3.5/5.0 stars

**Reviewed by:** Dan Q. | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 30, 2020

**What do you like best about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

Config Audit is great for rules testing, great for compliance. Client is easy to install.

**What do you dislike about F5 Distributed Cloud App Infrastructure Protection (AIP)?**

Host CVE vulnerabilties arent actionable. Some not patched, just declares they exist.

**What problems is F5 Distributed Cloud App Infrastructure Protection (AIP) solving and how is that benefiting you?**

Compliance Auditing. Some findings we were able to remediate.


## F5 Distributed Cloud App Infrastructure Protection (AIP) Discussions
  - [Is ThreatStack an ids?](https://www.g2.com/discussions/is-threatstack-an-ids)
  - [What does a Cspm do?](https://www.g2.com/discussions/what-does-a-cspm-do)
  - [Is Threat stack a SIEM?](https://www.g2.com/discussions/is-threat-stack-a-siem)
  - [What does Threat Stack do?](https://www.g2.com/discussions/what-does-threat-stack-do)

- [View F5 Distributed Cloud App Infrastructure Protection (AIP) pricing details and edition comparison](https://www.g2.com/products/f5-distributed-cloud-app-infrastructure-protection-aip/reviews?filters%5Bnps_score%5D%5B%5D=4&section=pricing&secure%5Bexpires_at%5D=2026-08-13+10%3A44%3A43+-0500&secure%5Bsession_id%5D=872af417-dec2-42cd-a60f-27521a4bf192&secure%5Btoken%5D=0ca0106efd23a49b1a86b64953700720eb4e401f69c01779efbbde17f92e9a5e&format=llm_user)

## F5 Distributed Cloud App Infrastructure Protection (AIP) Features
**Management**
- Dashboards and Reports
- Administration Console

**Administration**
- Security Auditing
- Configuration Management
- Metadata Management
- Policy Management
- Incident Management
- Vulnerability Management
- Compliance Management
- User Management
- Deployment Management
- Audit Management
- Patch Management
- Application Security
- Runtime Container Security

**Security**
- Compliance Monitoring
- Anomoly Detection
- Cloud Gap Analytics

**Activity Monitoring**
- API Monitoring
- Activity Monitoring

**Configuration**
- Configuration Monitoring
- Unified Policy Management
- API / Integrations

**Cloud Visibility**
- Cloud Gap Analytics

**Operations**
- Logging and Reporting
- API / Integrations

**Monitoring**
- Continuous Image Assurance
- Behavior Monitoring
- Observability
- Continuous Monitoring
- Real-Time Monitoring

**Compliance**
- Sensitive Data Compliance

**Security**
- Compliance Monitoring
- Risk Analysis
- Reporting

**Security**
- Security Auditing
- Real-Time Data
- Cloud Application Security
- SSL Security

**Security Controls **
- Anomaly Detection
- Security Auditing
- Cloud Gap Analytics

**Protection**
- Dynamic Image Scanning
- Runtime Protection
- Workload Protection
- Network Segmentation
- Container Scanning
- Vulnerability Scanning

**Administration**
- Auditing

**Administration**
- Security Automation
- Security Integration
- Multicloud Visibility

**Vulnerability Management**
- Threat Hunting
- Vulnerability Scanning
- Vulnerability Intelligence
- Risk-Prioritization

**Additional Functionality**
- Two-Factor Authentication
- Third-Party Integrations
- Intrusion Detection System
- Continuous Integration
- Customizable Reports
- Continuous Delivery
- Activity Dashboard
- Security Testing
- Audit Trail
- Risk Alerts
- Access Controls/Permissions
- API
- AI Copilot
- Continuous Deployment
- Threat Response
- Reporting & Statistics
- Authentication
- Encryption
- Threat Intelligence
- Risk Analysis
- For DevSecOps
- Generative AI
- Reporting/Analytics
- Container Isolation
- Risk Assessment
- Search/Filter
- Vulnerability/Threat Prioritization

**Identity**
- User Analytics
- Real-Time Analytics
- Visual Analytics
- Reporting/Analytics

**Agentic AI - Cloud Security Monitoring and Analytics**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Additional Functionality**
- Alerts/Notifications
- AI Copilot
- Access Controls/Permissions
- Endpoint Management
- Intrusion Detection System
- Compliance Management
- HIPAA Compliant
- Search/Filter
- API
- Two-Factor Authentication
- Data Visualization
- Risk Assessment
- Real-Time Monitoring
- Event Logs
- Activity Dashboard
- Audit Management
- Cloud Security Policy Management
- Vulnerability Protection
- Anti Virus
- Incident Management
- Threat Intelligence
- Real-Time Reporting
- Reporting & Statistics
- User Management
- Encryption
- Vulnerability Scanning
- Generative AI
- Status Tracking
- Third-Party Integrations
- Real-Time Notifications
- Patch Management
- Monitoring
- Cloud Encryption

## Top F5 Distributed Cloud App Infrastructure Protection (AIP) Alternatives
  - [FortiCNAPP](https://www.g2.com/products/forticnapp/reviews) - 4.4/5.0 (383 reviews)
  - [Orca Security](https://www.g2.com/products/orca-security/reviews) - 4.7/5.0 (315 reviews)
  - [Wiz](https://www.g2.com/products/wiz-wiz/reviews) - 4.7/5.0 (838 reviews)

